system

The system addresses the challenge of outdated fraud detection by automatically updating fraud models and providing real-time warnings, effectively protecting users from sophisticated internet fraud.

JP2026103389APending Publication Date: 2026-06-24SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
SOFTBANK GROUP CORP
Filing Date
2024-12-12
Publication Date
2026-06-24

AI Technical Summary

Technical Problem

Conventional fraud detection systems have low update frequencies and struggle to effectively counter new fraud methods, posing a significant risk to elderly and general users who are often targets of sophisticated internet fraud, leading to financial loss and mental stress.

Method used

A system that automatically collects information on the latest fraud methods from the internet, generates a model for detecting fraudulent activities using a generative model, and provides real-time warnings to users, with continuous improvement through user feedback.

Benefits of technology

Enables users to detect and prevent fraud promptly, reducing the risk of financial loss and mental stress by continuously updating the fraud detection model to counter new fraud techniques.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026103389000001_ABST
    Figure 2026103389000001_ABST
Patent Text Reader

Abstract

We provide the system. [Solution] Means of gathering information on the latest fraud techniques from various sources, A means for generating a model to detect fraudulent activity using a generative model based on collected information, A means for analyzing user information using the aforementioned model and detecting signs of fraud, A means of displaying a warning to the user based on the detected signs, A means to monitor users' communication data in real time and quickly warn them if there is a possibility of fraud, A system that includes this.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0004] , , , ,

[0005] , , , , ,

[0001] The technology of the present disclosure relates to a system.

Background Art

[0002] Patent Document 1 discloses a persona chatbot control method performed by at least one processor, including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance that responds to the user utterance.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In recent years, with the rapid spread of the Internet, fraud has become increasingly sophisticated. As a result, there is a problem that especially elderly people and general users who are not familiar with the Internet are likely to become targets of fraud. Not only financial damage due to fraud, but also serious effects such as mental stress and loss of social credit occur, so early detection and prevention of fraud are strongly demanded. In addition, there has been a problem that conventional fraud countermeasure systems have a low update frequency and it is difficult to counter new fraud methods emerging one after another. Therefore, there is a need for a flexible and effective fraud detection system that can always respond to the latest fraud methods.

Means for Solving the Problems

[0005] To solve the above problems, this invention provides a system that automatically collects information on the latest fraud methods from the internet and generates a model for detecting fraudulent activities using a generative model based on that information. Furthermore, this system can analyze the user's communication data in real time and immediately warn the user when signs of fraud are detected. In addition, by utilizing user feedback and continuously improving the generative model, it can respond to new fraud methods with high accuracy. This will enable users to continue to participate in the digital society with peace of mind.

[0006] "Latest fraud techniques" refer to the latest and most sophisticated methods of fraud, including newly emerging fraudulent tactics and technologies on the internet.

[0007] "Means of collecting information from the internet" refers to technologies that automatically collect data related to fraud from publicly available information on the internet using web scraping or APIs.

[0008] A "generative model" is a model that uses machine learning algorithms to learn specific patterns from input data and detect new fraudulent activities.

[0009] "User data" refers to communication data such as emails, messages, and call content received by the user, and is information that is analyzed to detect signs of fraud.

[0010] "Signs of fraud" are elements that are identified as characteristics or patterns common to other fraudulent activities, and these elements are used as indicators to judge the likelihood of fraud.

[0011] "Means of displaying warnings to users" refers to technologies that display notifications or pop-ups on a device to alert users to potential dangers when fraud is suspected.

[0012] "Feedback" refers to information collected from users regarding their experience using the system and the accuracy of warnings, which is then used to improve the system. [Brief explanation of the drawing]

[0013] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Figure 11] This is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] This is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] This is a sequence diagram showing the processing flow of the data processing system in Example 2, which incorporates an emotion engine. [Figure 14]It is a sequence diagram showing the processing flow of a data processing system in Application Example 2 when a sentiment engine is combined.

Mode for Carrying Out the Invention

[0014] Hereinafter, an example of an embodiment of a system according to the technology of the present disclosure will be described with reference to the accompanying drawings.

[0015] First, the terms used in the following description will be explained.

[0016] In the following embodiments, a numbered processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Also, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), and the like.

[0017] In the following embodiments, a numbered RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a work memory by the processor.

[0018] In the following embodiments, a numbered storage is one or more non-volatile storage devices that store various programs and various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes, etc.

[0019] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).

[0020] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."

[0021] [First Embodiment]

[0022] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.

[0023] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0024] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0025] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.

[0026] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0027] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0028] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.

[0029] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0030] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0031] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0032] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0033] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".

[0034] The system of this invention is integrated into the user's digital communication environment and provides a method for detecting and responding to fraud threats in real time. This system operates with a server and terminal working together to collect the latest fraud techniques and generate a detection model based on that information. It then analyzes communication content on the user's terminal and immediately alerts the user if signs of fraud are detected.

[0035] Server Role

[0036] The server collects fraud-related data from various sources on the internet. This includes samples of phishing emails and summaries of newly reported fraud techniques. The collected data allows the generative model to be kept constantly up-to-date. The server analyzes this data and trains machine learning models to generate models for detecting fraudulent activities with high accuracy.

[0037] Terminal role

[0038] The client program installed on the device monitors emails, messages, and call content with the user's consent. Based on a fraud detection model provided by the server, this program analyzes communication content and detects signs of fraud. Specifically, if it contains phishing links, malicious requests, or is determined to be communication from a suspicious sender, the device will display a warning. This warning includes specific instructions such as not opening the email or message or clicking on any links.

[0039] User experience

[0040] Users can view warnings displayed on their devices and take appropriate action based on their content. For example, they can delete emails displaying warnings or promptly hang up suspicious phone calls. Furthermore, the system receives feedback from users, which is used in the next model update. This improves the user experience and allows the system to evolve to respond quickly to new fraud trends.

[0041] For example, when a user receives an email stating, "Your account has been hacked," the device detects that this email is a sign of fraud. The system analyzes the email in real time, compares it to a database of fraudulent emails, and if it is deemed high-risk, a warning such as, "This email may be fraudulent. Do not open the attached link," is displayed. By following this advice and deleting the email, the user can prevent becoming a victim of fraud.

[0042] Thus, the system of the present invention provides users with protection from fraud and creates an environment in which they can use the digital society with peace of mind.

[0043] The following describes the processing flow.

[0044] Step 1:

[0045] The server regularly scans publicly available databases and related information sources on the internet to collect new fraud techniques and specific examples of them. This collection includes the use of web scraping techniques and external APIs.

[0046] Step 2:

[0047] The server analyzes the latest fraud-related data it has collected and uses it to train a generative model. This training process uses machine learning algorithms and aims to build a highly accurate model for detecting signs of fraud.

[0048] Step 3:

[0049] The device receives fraud detection models from the server and monitors the user's communication data (emails, messages, call content) in real time. This data is only collected after obtaining the user's permission.

[0050] Step 4:

[0051] The device analyzes user data based on a detection model to look for signs of fraud. This analysis uses text mining and speech recognition technologies to identify suspicious links, requests, and other elements.

[0052] Step 5:

[0053] If the device detects signs of fraud, it will immediately display a warning to the user. The warning message will specifically indicate the content of the relevant communication and include instructions on how the user should respond.

[0054] Step 6:

[0055] Users can review warnings from their devices and take appropriate action if necessary. This includes deleting the email, not opening any related links, or not replying to the sender.

[0056] Step 7:

[0057] The system collects user actions and responses to warnings as feedback and sends it to the server. This feedback is used for the next model training, contributing to improving the system's accuracy.

[0058] (Example 1)

[0059] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0060] In today's world, where internet-based communication is widespread, fraudulent activities are becoming more sophisticated and diverse. Traditional methods are insufficient to respond quickly to new fraudulent techniques, increasing the likelihood of users becoming victims. Furthermore, processes for maintaining and updating the accuracy of models used to detect fraudulent activity are not yet fully established. Therefore, new methods are needed to effectively protect users from fraud.

[0061] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0062] In this invention, the server includes means for collecting information on fraudulent methods in digital communications from a communication network, means for generating a logical structure for detecting fraudulent activity using a machine learning model generated based on the collected information, and means for analyzing user information using the logical structure to detect signs of fraudulent activity. This makes it possible to respond quickly to the latest fraudulent methods and effectively protect users from fraud.

[0063] "Digital communication" refers to sending and receiving information via the internet or other electronic communication technologies.

[0064] "Fraudulent methods" refer to dishonest methods or techniques used to deceive others.

[0065] "Communication network" refers to the entire infrastructure for transmitting information, namely the internet and other digital networks.

[0066] A "machine learning model" refers to a mathematical algorithm that learns from data and makes predictions and decisions about future instances.

[0067] A "logical structure" refers to a combination of information and processes used to achieve a certain objective, and the framework for analyzing data and deriving meaningful conclusions based on that structure.

[0068] "User" refers to an individual or legal entity that uses this system.

[0069] "Misconduct" refers to unacceptable actions that use means that violate laws or ethics.

[0070] "Evaluation" refers to opinions and feedback provided by users, and it provides information that contributes to improving the system.

[0071] "Immediate" refers to an action being performed within a very short timeframe, meaning there is virtually no time delay.

[0072] In this embodiment of the invention, a system is constructed to protect users from fraudulent activities by having a server and a terminal cooperate.

[0073] The server collects information about fraudulent practices from various data sources on the communication network. This includes publicly available data from websites, social media, and news platforms. The collected information is filtered and cleaned using data analysis software and then fed into machine learning algorithms. Based on this information, the server generates constantly updated machine learning models and uses these models to develop highly accurate fraud detection logic. This model is delivered to the device via a cloud storage service.

[0074] The terminal has a client program installed that monitors communication data with the user's permission. The terminal analyzes emails and messages in real time and evaluates the data based on a fraud detection model provided by the server. For example, if an email received contains a typical fraudulent phrase such as "Your account is at risk," the terminal will notify the user to warn them.

[0075] A concrete example of a prompt message would be, "What are effective sources of information for collecting data on new phishing techniques and updating the fraud detection model?" This serves as input for the system to constantly optimize the model based on the latest data.

[0076] Users can review warnings displayed on their devices and take measures such as deleting potentially fraudulent emails based on the information provided. This allows users to use digital communications with peace of mind. A feedback function sends user information to the server, which is then used to improve the system in the future. In this way, the system provides concrete solutions to efficiently protect users from fraud.

[0077] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0078] Step 1:

[0079] The server collects data on fraudulent methods from various sources on the communication network. Specifically, the server extracts information using relevant keywords from news sites, forums, social media, etc. The input to this process is a list of keywords related to fraud, and the output is text data about fraudulent methods. Web scraping techniques are used for data collection.

[0080] Step 2:

[0081] The server analyzes, filters, and cleans the collected data. The input is the collected, raw fraud-related data, and the output is a clean, structured dataset. Data analysis tools are used to remove noise and normalize the data, preparing it for machine learning.

[0082] Step 3:

[0083] The server trains a machine learning model based on the cleaned data. The input is a filtered dataset, and the output is a fraud detection model. Generative AI modeling techniques are used to train the model, learning diverse fraud patterns and building a highly accurate logical structure.

[0084] Step 4:

[0085] The server delivers the latest fraud detection model to the device via cloud storage. The input is the trained fraud detection model, and the output is the model data stored on the device. Delivery is performed regularly to ensure that the latest model is always available on the device.

[0086] Step 5:

[0087] The terminal's client program monitors and analyzes message data in real time. The input is the user's communication content (e.g., emails or messages), and the output is a judgment regarding detected signs of fraud. Based on a model delivered from the server, the terminal analyzes the communication content and detects signs of fraud.

[0088] Step 6:

[0089] The device will warn the user if signs of fraud are detected. The input is communication data that has been determined to be potentially fraudulent, and the output is a warning message to the user. Specifically, it will display a warning message in a pop-up to alert the user. For example, it may display something like, "This email may be fraudulent, so do not open the link."

[0090] Step 7:

[0091] Users take fraud prevention measures based on warnings from their devices. The input is the warning message from the device, and the output is the user's response. Examples include deleting the email in question or not clicking on suspicious links. Users can also report their decisions to the system using the feedback function.

[0092] In this way, throughout each step, the server and terminal work closely together to implement a process that protects users from fraudulent activities.

[0093] (Application Example 1)

[0094] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0095] In today's digital communication environment, fraudulent methods are becoming increasingly sophisticated, making it difficult for users to deal with these threats. In particular, detecting signs of fraud in real time and providing appropriate warnings before users become victims is a critical challenge. There is a need to provide rapid and effective defenses against such fraudulent activities.

[0096] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0097] In this invention, the server includes means for collecting information on the latest fraudulent methods from information sources, means for generating a model for detecting fraudulent activity using a generative model based on the collected information, and means for analyzing user information using the model to detect signs of fraud. This makes it possible to monitor the user's communication data in real time and to quickly warn in the event of potential fraud.

[0098] "Information source" refers to a data provider used to collect information about fraudulent methods.

[0099] A "generative model" is a mechanism for creating predictive algorithms to detect fraudulent activity based on collected data.

[0100] "User" refers to an individual or organization that uses the fraud detection system.

[0101] "Signs of fraud" are specific patterns or indicators that suggest fraudulent activity may be taking place.

[0102] A "warning" is a notification that informs users of the possibility of fraud and serves as a cautionary tale.

[0103] "Communication data" refers to information that users send and receive in digital communications, such as emails, messages, and phone calls.

[0104] "Mobile device" refers to electronic devices such as smartphones and tablets that users can carry with them.

[0105] "Head-mounted display devices" refer to devices such as smart glasses and head-mounted displays that are worn and used by the user.

[0106] The system realizing this invention involves a server and a terminal working together to detect and warn of signs of fraud in real time. The server collects information on fraudulent methods from various sources and uses this information to generate an advanced predictive model for detecting fraudulent activity using a generative model. The generated model is transmitted to the terminal. On the terminal, the user's communication data is monitored in real time, and if signs of fraud are found, a warning is issued quickly. The warning is displayed on the user's mobile device or a head-mounted display device.

[0107] Specifically, the server uses Python or a similar programming environment to analyze diverse data sources on the internet and learn signs of phishing emails and other fraudulent activities. On the terminal side, the collected models are used to analyze emails and messages contained in communications and assess the fraud risk. This allows users to instantly recognize emails containing suspicious links and prevent fraud before it happens.

[0108] For example, when a user receives a message stating, "Your account has been accessed without authorization," the device analyzes this message in real time. If a high risk of fraud is detected, it immediately displays a warning such as, "This message may be a scam." This allows the user to act safely without clicking on any links.

[0109] Examples of prompt messages include the following:

[0110] "Detect whether the following message is a fraud: 'You've won a free vacation. Click here to claim your prize.'"

[0111] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0112] Step 1:

[0113] The server collects data on fraudulent methods from internet sources. Inputs include phishing emails, URLs of fraudulent websites, and summaries of reported fraud cases. This information is collected and stored in a database to prepare the foundational data for generating highly accurate fraud detection models. The output is updates to the fraudulent methods database.

[0114] Step 2:

[0115] The server trains a generative AI model based on the collected data. The input is the fraud-related data collected in Step 1. This is fed into a machine learning algorithm to generate a model for detecting fraudulent activity. During this process, data processing steps such as feature extraction and data normalization are performed. The output is the newly trained fraud detection model.

[0116] Step 3:

[0117] The server sends the trained fraud detection model to the terminal. The input is the fraud detection model generated in step 2. The output is the state change of the terminal, which has received the model and is preparing for analysis.

[0118] Step 4:

[0119] The device monitors the user's communication data in real time using the received fraud detection model. Inputs include emails, messages, and call content sent and received by the user. This data is analyzed in real time to detect signs of fraud. The output is information about the detected signs of fraud.

[0120] Step 5:

[0121] The device immediately displays a warning to the user if signs of fraud are detected. The input is the fraud indicator data obtained in step 4. Based on this data, a warning message is generated to help the user take appropriate action and displayed on the mobile device or head-mounted display device. The output is the warning displayed to the user and the corresponding user action.

[0122] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0123] This invention's system incorporates an emotion engine that recognizes user emotions in addition to a fraud detection function. This allows the system to analyze the user's emotional state based on the detected signs of fraud while the user is using digital communication, and then provide an appropriate response.

[0124] Server Role

[0125] The server collects the latest fraud information from the internet and generates models to detect fraudulent activities. In addition, it prepares the data necessary for the emotion engine and provides a foundation for analyzing the user's emotional state.

[0126] Terminal role

[0127] The device operates using a fraud detection model and sentiment engine provided by the server. With the user's permission, it monitors communication data, voice, and data related to the user's emotions. This data is analyzed in real time to look for signs of fraud.

[0128] The emotion engine identifies the user's emotional state from factors such as voice tone, text content, and behavioral patterns. If fraud is detected and it is determined that the user is experiencing anxiety or stress as a result, the system takes this into account and provides the user with an appropriate warning.

[0129] User feedback and response

[0130] Users can receive emotionally-sensitive advice through warning messages on their devices. For example, if a user is feeling stressed, the warning may be delivered in a gentle tone or display additional support information (such as who they can talk to).

[0131] Specific example

[0132] For example, if a user receives an email requesting an urgent account information update, the device analyzes the email and determines that it is likely a scam. The emotion engine may simultaneously detect that the user's heart rate has increased and they are feeling anxious while reading the email. In this case, the device displays a warning message tailored to the user's emotional state, such as, "This email may be a scam. Please remain calm and contact our support center."

[0133] Furthermore, user feedback is sent to the server and used to improve the fraud detection model and sentiment engine. This allows the system to continuously improve the user experience and strengthen protection against fraud.

[0134] The introduction of this system will reduce the risk of fraud for users, allowing them to continue using the digital world with peace of mind.

[0135] The following describes the processing flow.

[0136] Step 1:

[0137] The server collects data on the latest fraud techniques from publicly available databases on the internet and related sources. This information includes phishing email samples and new fraud methods.

[0138] Step 2:

[0139] The server analyzes the collected data and builds a generative model to detect fraudulent activity. This model is trained using machine learning algorithms to improve its ability to identify new signs of fraud.

[0140] Step 3:

[0141] The server uses an emotion engine to prepare training data for emotion recognition and lay the foundation for understanding various human emotional states.

[0142] Step 4:

[0143] The device receives fraud detection models and sentiment engines provided by the server and monitors the user's communication data in real time. This data includes emails, messages, and voice data.

[0144] Step 5:

[0145] The device uses a fraud detection model to analyze the user's communication data and detect signs of fraud. If a fraudulent email or suspicious link is detected, the information is recorded in detail.

[0146] Step 6:

[0147] The device's emotion engine analyzes the user's emotions from their voice tone and text content. For example, it can determine whether a user is feeling anxious while reading an email.

[0148] Step 7:

[0149] The device will display an emotionally appropriate warning to the user if signs of fraud are detected and the user is feeling anxious. This warning will include appropriate countermeasures and support information.

[0150] Step 8:

[0151] Users review the displayed warnings and select safe actions as needed. For example, they might delete emails suspected of being fraudulent.

[0152] Step 9:

[0153] The user's actions and responses to warnings are sent to the server as feedback. This feedback is used to further improve the generative model and sentiment engine.

[0154] (Example 2)

[0155] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".

[0156] Traditional fraud detection systems focus on detecting signs of fraud, but they are unable to respond in a way that aligns with the emotional state of users affected by detected fraud. As a result, users' stress and anxiety remain unresolved, and the optimal response is not provided.

[0157] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0158] In this invention, the server includes means for collecting information on the latest fraudulent methods from a communication network, means for generating a model for identifying fraudulent activities using a generative model based on the collected information, and means for identifying the user's emotional state using an emotion analysis device. This makes it possible to provide appropriate warnings and responses according to the user's emotional state, enabling the user to use the digital environment with peace of mind.

[0159] "Communication network" refers to the infrastructure and technologies used to send and receive information, and in particular includes the internet and other digital networks.

[0160] A "generative model" refers to a machine learning model that learns patterns from data and is built to make predictions and classifications on new data.

[0161] "Fraudulent activity" refers to any action or means taken to deceive others with dishonesty or malicious intent.

[0162] An "emotion analysis device" refers to a system that includes technologies and devices that analyze voice, text, behavioral patterns, etc., in order to identify a user's emotional state.

[0163] "Users" refers to individuals or organizations that use the system to provide information or receive services.

[0164] "Real-time" refers to data processing and analysis being carried out in accordance with the passage of time in the real world, meaning that delays are minimized.

[0165] A "warning" refers to a notification or message provided by a system to inform the user of potential dangers or situations that require attention.

[0166] This invention is an advanced digital protection system that combines fraud detection and sentiment recognition. The server automatically acquires data on the latest fraud patterns and techniques from an information network. Based on the collected information, the server builds a fraud detection model using programming languages ​​such as Python and libraries such as Scikit-learn and TENSORFLOW®. This model learns patterns to identify fraudulent activities and analyzes user data. Furthermore, the server prepares the data necessary for sentiment analysis devices and provides a foundation for identifying the user's emotional state.

[0167] The terminal utilizes fraud detection models and sentiment analysis devices provided by the server. With the user's permission, the terminal monitors communication and voice data in real time and analyzes signs of fraud. The sentiment engine implemented on the terminal analyzes voice tone, text content, and behavioral patterns to identify the user's emotional state. Specific software used includes NLTK and Hugging Face Transformers.

[0168] For example, when a user receives an email requesting an urgent account information update, the device immediately analyzes the email's content and detects that it is likely a scam. Simultaneously, the emotion engine may detect an increase in heart rate and determine that the user is feeling anxious. In such cases, the device displays an emotion-sensitive warning message such as, "This email may be a scam. Please remain calm and contact the appropriate department." Examples of these prompts may include, "Please describe the characteristics of a scam email," or "What can help the user feel at ease?"

[0169] Users can receive warnings and advice from the system and provide feedback. This feedback is sent to the server and used to improve the accuracy of the fraud detection model and sentiment analysis device. This allows the system to continuously evolve and provide users with a safer and more comfortable digital experience.

[0170] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0171] Step 1:

[0172] The server retrieves data on the latest fraud patterns from its information network. It uses a list of URLs from news sites and specialized databases as input, collecting information using web scraping techniques. The output is a dataset containing characteristics and related information of fraudulent methods. This dataset is used in the subsequent model generation process.

[0173] Step 2:

[0174] The server builds a generative AI model based on the data collected in Step 1. It receives a dataset of fraud features as input and trains the model using machine learning algorithms with Scikit-learn or TensorFlow. The output is a classification model for fraud detection. This model is used to distinguish between fraud and normal behavior.

[0175] Step 3:

[0176] The server prepares data for the emotion analysis device. It collects emotion label information based on speech and text as input, and constructs a dataset using NLTK and Hugging Face Transformers. The output is a dataset that serves as a baseline for identifying the user's emotional state. This dataset is used for emotion analysis on the terminal.

[0177] Step 4:

[0178] The terminal receives a fraud detection model and sentiment analysis device provided by the server and executes them on the user's device. It monitors the user's communication data and voice data as input. The output is real-time fraud detection results and identification of emotional states. Specifically, it analyzes emails and call content to immediately identify signs of fraud and changes in emotion.

[0179] Step 5:

[0180] The device generates and displays a warning message to the user based on detected fraud signs and emotional state. It uses the results of fraud model detection and sentiment analysis as input. The output is a customized warning message tailored to the user's situation, such as, "This may be a scam. Please remain calm."

[0181] Step 6:

[0182] Users receive warnings from their devices, take necessary actions, and provide feedback based on their experience. Input consists of the warning content and the user's personal response experience, which are used to generate feedback. Output is improvement suggestions and experience evaluations sent to the server. This feedback is used for the continuous improvement of the system.

[0183] (Application Example 2)

[0184] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as a "server" and the smart device 14 as a "terminal".

[0185] In modern electronic financial transactions, fraudulent activities are becoming increasingly sophisticated, making it difficult for users to trade online with confidence. Furthermore, users who encounter signs of fraud often experience anxiety and stress, which can impair their ability to make rational decisions. In this context, there is a need not only to quickly detect signs of fraud but also to provide appropriate warnings and support that take into account the user's emotional state.

[0186] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[0187] In this invention, the server includes means for collecting information on the latest fraudulent methods from the internet, means for generating a model for detecting fraudulent activity using a generative model based on the collected information, and means for analyzing user information using the model to detect signs of fraud. This makes it possible to analyze the user's communication information in real time and immediately issue a warning, taking into account the emotional state, if there is a possibility of fraud.

[0188] "Fraudulent practices" are means or techniques used to deceive users and extort money or personal information from them.

[0189] A "generative model" is a method for generating algorithms to detect fraudulent activity using collected data.

[0190] "Emotional state" refers to the user's psychological and physiological emotional state, which includes anxiety, stress, tension, etc.

[0191] "Adjusting the wording of warnings" means changing the content and tone of warning messages according to the user's emotional state.

[0192] "Communication information" refers to data that users send and receive through electronic devices, and includes voice, text, and other digital information.

[0193] "Real-time analysis" means processing the data almost instantly after it is acquired and obtaining the results.

[0194] The system for implementing this invention is intended to consist of a server and terminals, and to operate in coordination with each other.

[0195] The server is responsible for collecting information on the latest fraud techniques from the internet. This is done through web crawling technologies and APIs, and stored in a database as needed. Based on this information, the server uses AI generative models (e.g., custom models using TensorFlow) to generate analytical models for detecting fraudulent activity. For analyzing emotional states, it uses speech analysis libraries (e.g., Google® Speech-to-Text API).

[0196] The terminal retrieves the generative model from the server and analyzes the user's communication information (voice, text, etc.) in real time. If signs of fraud are detected through this analysis, the emotional state is evaluated. For example, changes in voice or behavioral patterns are interpreted as emotional states. Based on this emotional state, the terminal adjusts the content and tone of the warning message and presents it to the user. This helps the user to calmly assess the situation.

[0197] Users can submit feedback on warnings provided from their devices. This feedback is returned to the server and used to improve the fraud detection and sentiment analysis models. By collecting and applying feedback, the system is continuously updated, enabling more sophisticated fraud prevention measures.

[0198] As a concrete example, when a user attempts to purchase an expensive item from a new online shop, the device analyzes the transaction and, if it determines there is a high risk of fraud, checks the user's emotional state. For instance, if it detects signs of anxiety and an elevated heart rate, the device displays a gentle message such as, "This transaction carries a risk of fraud. Further details are recommended."

[0199] An example of a prompt message is: "A user is attempting to make a large online payment. If there are signs of fraud, how should a warning be issued? Also, design an effective, emotion-based warning message."

[0200] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0201] Step 1:

[0202] The server collects information about fraudulent methods from the internet. Using web crawling technology and APIs, it retrieves the latest fraud-related data and stores it in a database. This prepares the information in a format that can be used to generate fraud models.

[0203] Step 2:

[0204] The server creates a fraud detection model using a generative AI model (e.g., TensorFlow) based on the collected data. The latest fraud information is used as input, and the detection model is obtained as output. The generated model is then used to analyze user data.

[0205] Step 3:

[0206] The device retrieves a fraud detection model from the server and begins real-time analysis of the user's communication information (voice, text, etc.). It analyzes the user's communication data as input and outputs a detection result if there are signs of fraud.

[0207] Step 4:

[0208] The device evaluates the user's emotional state in response to detected signs of fraud. Using a speech analysis library (e.g., Google Speech-to-Text API), it analyzes the emotional state using voice tone and behavioral patterns as input. Based on this, changes in emotion are output.

[0209] Step 5:

[0210] The device adjusts warning messages based on the analyzed emotional state. It receives the emotional state and fraud detection results as input and generates and displays a warning with appropriate content and tone to the user.

[0211] Step 6:

[0212] The user reviews the warning message displayed on the device and provides feedback as needed. The user's feedback is sent to the server for system improvement. The user's response is received as input, and feedback information is returned to the server.

[0213] Step 7:

[0214] The server updates its fraud detection and sentiment analysis models based on user feedback. Feedback information is provided as input, which adjusts the models, resulting in improved models as output. This cycle allows the system to continuously improve.

[0215] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0216] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0217] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.

[0218] [Second Embodiment]

[0219] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.

[0220] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0221] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0222] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.

[0223] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0224] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0225] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0226] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0227] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0228] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0229] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0230] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0231] The system of this invention is integrated into the user's digital communication environment and provides a method for detecting and responding to fraud threats in real time. This system operates with a server and terminal working together to collect the latest fraud techniques and generate a detection model based on that information. It then analyzes communication content on the user's terminal and immediately alerts the user if signs of fraud are detected.

[0232] Server Role

[0233] The server collects fraud-related data from various sources on the internet. This includes samples of phishing emails and summaries of newly reported fraud techniques. The collected data allows the generative model to be kept constantly up-to-date. The server analyzes this data and trains machine learning models to generate models for detecting fraudulent activities with high accuracy.

[0234] Terminal role

[0235] The client program installed on the device monitors emails, messages, and call content with the user's consent. Based on a fraud detection model provided by the server, this program analyzes communication content and detects signs of fraud. Specifically, if it contains phishing links, malicious requests, or is determined to be communication from a suspicious sender, the device will display a warning. This warning includes specific instructions such as not opening the email or message or clicking on any links.

[0236] User experience

[0237] Users can view warnings displayed on their devices and take appropriate action based on their content. For example, they can delete emails displaying warnings or promptly hang up suspicious phone calls. Furthermore, the system receives feedback from users, which is used in the next model update. This improves the user experience and allows the system to evolve to respond quickly to new fraud trends.

[0238] For example, when a user receives an email stating, "Your account has been hacked," the device detects that this email is a sign of fraud. The system analyzes the email in real time, compares it to a database of fraudulent emails, and if it is deemed high-risk, a warning such as, "This email may be fraudulent. Do not open the attached link," is displayed. By following this advice and deleting the email, the user can prevent becoming a victim of fraud.

[0239] Thus, the system of the present invention provides users with protection from fraud and creates an environment in which they can use the digital society with peace of mind.

[0240] The following describes the processing flow.

[0241] Step 1:

[0242] The server regularly scans publicly available databases and related information sources on the internet to collect new fraud techniques and specific examples of them. This collection includes the use of web scraping techniques and external APIs.

[0243] Step 2:

[0244] The server analyzes the latest fraud-related data it has collected and uses it to train a generative model. This training process uses machine learning algorithms and aims to build a highly accurate model for detecting signs of fraud.

[0245] Step 3:

[0246] The device receives fraud detection models from the server and monitors the user's communication data (emails, messages, call content) in real time. This data is only collected after obtaining the user's permission.

[0247] Step 4:

[0248] The device analyzes user data based on a detection model to look for signs of fraud. This analysis uses text mining and speech recognition technologies to identify suspicious links, requests, and other elements.

[0249] Step 5:

[0250] If the device detects signs of fraud, it will immediately display a warning to the user. The warning message will specifically indicate the content of the relevant communication and include instructions on how the user should respond.

[0251] Step 6:

[0252] Users can review warnings from their devices and take appropriate action if necessary. This includes deleting the email, not opening any related links, or not replying to the sender.

[0253] Step 7:

[0254] The system collects user actions and responses to warnings as feedback and sends it to the server. This feedback is used for the next model training, contributing to improving the system's accuracy.

[0255] (Example 1)

[0256] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0257] In today's world, where internet-based communication is widespread, fraudulent activities are becoming more sophisticated and diverse. Traditional methods are insufficient to respond quickly to new fraudulent techniques, increasing the likelihood of users becoming victims. Furthermore, processes for maintaining and updating the accuracy of models used to detect fraudulent activity are not yet fully established. Therefore, new methods are needed to effectively protect users from fraud.

[0258] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0259] In this invention, the server includes means for collecting information on fraudulent methods in digital communications from a communication network, means for generating a logical structure for detecting fraudulent activity using a machine learning model generated based on the collected information, and means for analyzing user information using the logical structure to detect signs of fraudulent activity. This makes it possible to respond quickly to the latest fraudulent methods and effectively protect users from fraud.

[0260] "Digital communication" refers to sending and receiving information via the internet or other electronic communication technologies.

[0261] "Fraudulent methods" refer to dishonest methods or techniques used to deceive others.

[0262] "Communication network" refers to the entire infrastructure for transmitting information, namely the internet and other digital networks.

[0263] A "machine learning model" refers to a mathematical algorithm that learns from data and makes predictions and decisions about future instances.

[0264] A "logical structure" refers to a combination of information and processes used to achieve a certain objective, and the framework for analyzing data and deriving meaningful conclusions based on that structure.

[0265] "User" refers to an individual or legal entity that uses this system.

[0266] "Misconduct" refers to unacceptable actions that use means that violate laws or ethics.

[0267] "Evaluation" refers to opinions and feedback provided by users, and it provides information that contributes to improving the system.

[0268] "Immediate" refers to an action being performed within a very short timeframe, meaning there is virtually no time delay.

[0269] In this embodiment of the invention, a system is constructed to protect users from fraudulent activities by having a server and a terminal cooperate.

[0270] The server collects information about fraudulent practices from various data sources on the communication network. This includes publicly available data from websites, social media, and news platforms. The collected information is filtered and cleaned using data analysis software and then fed into machine learning algorithms. Based on this information, the server generates constantly updated machine learning models and uses these models to develop highly accurate fraud detection logic. This model is delivered to the device via a cloud storage service.

[0271] The terminal has a client program installed that monitors communication data with the user's permission. The terminal analyzes emails and messages in real time and evaluates the data based on a fraud detection model provided by the server. For example, if an email received contains a typical fraudulent phrase such as "Your account is at risk," the terminal will notify the user to warn them.

[0272] A concrete example of a prompt message would be, "What are effective sources of information for collecting data on new phishing techniques and updating the fraud detection model?" This serves as input for the system to constantly optimize the model based on the latest data.

[0273] Users can review warnings displayed on their devices and take measures such as deleting potentially fraudulent emails based on the information provided. This allows users to use digital communications with peace of mind. A feedback function sends user information to the server, which is then used to improve the system in the future. In this way, the system provides concrete solutions to efficiently protect users from fraud.

[0274] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0275] Step 1:

[0276] The server collects data on fraudulent methods from various sources on the communication network. Specifically, the server extracts information using relevant keywords from news sites, forums, social media, etc. The input to this process is a list of keywords related to fraud, and the output is text data about fraudulent methods. Web scraping techniques are used for data collection.

[0277] Step 2:

[0278] The server analyzes, filters, and cleans the collected data. The input is the collected, raw fraud-related data, and the output is a clean, structured dataset. Data analysis tools are used to remove noise and normalize the data, preparing it for machine learning.

[0279] Step 3:

[0280] The server trains a machine learning model based on the cleaned data. The input is a filtered dataset, and the output is a fraud detection model. Generative AI modeling techniques are used to train the model, learning diverse fraud patterns and building a highly accurate logical structure.

[0281] Step 4:

[0282] The server distributes the latest fraud detection model to the terminal through cloud storage. The input is the trained fraud detection model, and the output is the model data stored on the terminal. The distribution is performed regularly so that the terminal can always utilize the latest model.

[0283] Step 5:

[0284] The client program on the terminal monitors and analyzes the telegram data in real time. The input is the user's communication content (such as emails or messages), and the output is the judgment on the detected signs of fraud. The terminal analyzes the communication content based on the model distributed by the server and performs the operation of detecting the signs of fraud.

[0285] Step 6:

[0286] When the terminal detects signs of fraud, it issues a warning to the user. The input is the communication data judged to have the possibility of fraud, and the output is the warning message to the user. As a specific operation, a warning message is displayed in a pop-up window to prompt the user's attention. For example, a message such as "This email may be fraudulent, so please do not click on the link" is displayed.

[0287] Step 7:

[0288] Based on the warning from the terminal, the user takes fraud prevention measures. The input is the warning message from the terminal, and the output is the user's response actions. For example, it includes deleting the corresponding email and not clicking on suspicious links. It is also possible to report the user's judgment result to the system using the feedback function

[0289] In this way, through each step, the server and the terminal cooperate closely to realize a process for protecting users from fraud

[0290] [[ID=,34]](Application Example 1)

[0291] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0292] In today's digital communication environment, fraudulent methods are becoming increasingly sophisticated, making it difficult for users to deal with these threats. In particular, detecting signs of fraud in real time and providing appropriate warnings before users become victims is a critical challenge. There is a need to provide rapid and effective defenses against such fraudulent activities.

[0293] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0294] In this invention, the server includes means for collecting information on the latest fraudulent methods from information sources, means for generating a model for detecting fraudulent activity using a generative model based on the collected information, and means for analyzing user information using the model to detect signs of fraud. This makes it possible to monitor the user's communication data in real time and to quickly warn in the event of potential fraud.

[0295] "Information source" refers to a data provider used to collect information about fraudulent methods.

[0296] A "generative model" is a mechanism for creating predictive algorithms to detect fraudulent activity based on collected data.

[0297] "User" refers to an individual or organization that uses the fraud detection system.

[0298] "Signs of fraud" are specific patterns or indicators that suggest fraudulent activity may be taking place.

[0299] A "warning" is a notification that informs users of the possibility of fraud and serves as a cautionary tale.

[0300] "Communication data" refers to information that users send and receive in digital communications, such as emails, messages, and phone calls.

[0301] "Mobile device" refers to electronic devices such as smartphones and tablets that users can carry with them.

[0302] "Head-mounted display devices" refer to devices such as smart glasses and head-mounted displays that are worn and used by the user.

[0303] The system realizing this invention involves a server and a terminal working together to detect and warn of signs of fraud in real time. The server collects information on fraudulent methods from various sources and uses this information to generate an advanced predictive model for detecting fraudulent activity using a generative model. The generated model is transmitted to the terminal. On the terminal, the user's communication data is monitored in real time, and if signs of fraud are found, a warning is issued quickly. The warning is displayed on the user's mobile device or a head-mounted display device.

[0304] Specifically, the server uses Python or a similar programming environment to analyze diverse data sources on the internet and learn signs of phishing emails and other fraudulent activities. On the terminal side, the collected models are used to analyze emails and messages contained in communications and assess the fraud risk. This allows users to instantly recognize emails containing suspicious links and prevent fraud before it happens.

[0305] For example, when a user receives a message stating, "Your account has been accessed without authorization," the device analyzes this message in real time. If a high risk of fraud is detected, it immediately displays a warning such as, "This message may be a scam." This allows the user to act safely without clicking on any links.

[0306] Examples of prompt messages include the following:

[0307] "Detect whether the following message is a fraud: 'You’ve won a free vacation. Click here to claim your prize.'"

[0308] The flow of the specific process in Application Example 1 will be described using FIG. 12.

[0309] Step 1:

[0310] The server collects data on fraud methods from information sources on the Internet. Inputs include phishing emails, URLs of fraud sites, summaries of reported fraud cases, etc. By collecting this information and storing it in a database, it prepares the basic data for generating a high-precision fraud detection model. The output is an update within the fraud method database.

[0311] Step 2:

[0312] The server trains a generated AI model based on the collected data. The input is the fraud-related data collected in Step 1. This is input into a machine learning algorithm to generate a model for detecting fraud behavior. At this time, data processing steps such as feature extraction and data normalization are performed. The output is a newly trained fraud detection model.

[0313] Step 3:

[0314] The server sends the trained fraud detection model to the terminal. The input is the fraud detection model generated in Step 2. The output is a change in the state of the terminal that receives the model and prepares for analysis.

[0315] Step 4:

[0316] The device monitors the user's communication data in real time using the received fraud detection model. Inputs include emails, messages, and call content sent and received by the user. This data is analyzed in real time to detect signs of fraud. The output is information about the detected signs of fraud.

[0317] Step 5:

[0318] The device immediately displays a warning to the user if signs of fraud are detected. The input is the fraud indicator data obtained in step 4. Based on this data, a warning message is generated to help the user take appropriate action and displayed on the mobile device or head-mounted display device. The output is the warning displayed to the user and the corresponding user action.

[0319] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0320] This invention's system incorporates an emotion engine that recognizes user emotions in addition to a fraud detection function. This allows the system to analyze the user's emotional state based on the detected signs of fraud while the user is using digital communication, and then provide an appropriate response.

[0321] Server Role

[0322] The server collects the latest fraud information from the internet and generates models to detect fraudulent activities. In addition, it prepares the data necessary for the emotion engine and provides a foundation for analyzing the user's emotional state.

[0323] Terminal role

[0324] The device operates using a fraud detection model and sentiment engine provided by the server. With the user's permission, it monitors communication data, voice, and data related to the user's emotions. This data is analyzed in real time to look for signs of fraud.

[0325] The emotion engine identifies the user's emotional state from factors such as voice tone, text content, and behavioral patterns. If fraud is detected and it is determined that the user is experiencing anxiety or stress as a result, the system takes this into account and provides the user with an appropriate warning.

[0326] User feedback and response

[0327] Users can receive emotionally-sensitive advice through warning messages on their devices. For example, if a user is feeling stressed, the warning may be delivered in a gentle tone or display additional support information (such as who they can talk to).

[0328] Specific example

[0329] For example, if a user receives an email requesting an urgent account information update, the device analyzes the email and determines that it is likely a scam. The emotion engine may simultaneously detect that the user's heart rate has increased and they are feeling anxious while reading the email. In this case, the device displays a warning message tailored to the user's emotional state, such as, "This email may be a scam. Please remain calm and contact our support center."

[0330] Furthermore, user feedback is sent to the server and used to improve the fraud detection model and sentiment engine. This allows the system to continuously improve the user experience and strengthen protection against fraud.

[0331] The introduction of this system will reduce the risk of fraud for users, allowing them to continue using the digital world with peace of mind.

[0332] The following describes the processing flow.

[0333] Step 1:

[0334] The server collects data on the latest fraud techniques from publicly available databases on the internet and related sources. This information includes phishing email samples and new fraud methods.

[0335] Step 2:

[0336] The server analyzes the collected data and builds a generative model to detect fraudulent activity. This model is trained using machine learning algorithms to improve its ability to identify new signs of fraud.

[0337] Step 3:

[0338] The server uses an emotion engine to prepare training data for emotion recognition and lay the foundation for understanding various human emotional states.

[0339] Step 4:

[0340] The device receives fraud detection models and sentiment engines provided by the server and monitors the user's communication data in real time. This data includes emails, messages, and voice data.

[0341] Step 5:

[0342] The device uses a fraud detection model to analyze the user's communication data and detect signs of fraud. If a fraudulent email or suspicious link is detected, the information is recorded in detail.

[0343] Step 6:

[0344] The device's emotion engine analyzes the user's emotions from their voice tone and text content. For example, it can determine whether a user is feeling anxious while reading an email.

[0345] Step 7:

[0346] The device will display an emotionally appropriate warning to the user if signs of fraud are detected and the user is feeling anxious. This warning will include appropriate countermeasures and support information.

[0347] Step 8:

[0348] Users review the displayed warnings and select safe actions as needed. For example, they might delete emails suspected of being fraudulent.

[0349] Step 9:

[0350] The user's actions and responses to warnings are sent to the server as feedback. This feedback is used to further improve the generative model and sentiment engine.

[0351] (Example 2)

[0352] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0353] Traditional fraud detection systems focus on detecting signs of fraud, but they are unable to respond in a way that aligns with the emotional state of users affected by detected fraud. As a result, users' stress and anxiety remain unresolved, and the optimal response is not provided.

[0354] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0355] In this invention, the server includes means for collecting information on the latest fraudulent methods from a communication network, means for generating a model for identifying fraudulent activities using a generative model based on the collected information, and means for identifying the user's emotional state using an emotion analysis device. This makes it possible to provide appropriate warnings and responses according to the user's emotional state, enabling the user to use the digital environment with peace of mind.

[0356] "Communication network" refers to the infrastructure and technologies used to send and receive information, and in particular includes the internet and other digital networks.

[0357] A "generative model" refers to a machine learning model that learns patterns from data and is built to make predictions and classifications on new data.

[0358] "Fraudulent activity" refers to any action or means taken to deceive others with dishonesty or malicious intent.

[0359] An "emotion analysis device" refers to a system that includes technologies and devices that analyze voice, text, behavioral patterns, etc., in order to identify a user's emotional state.

[0360] "Users" refers to individuals or organizations that use the system to provide information or receive services.

[0361] "Real-time" refers to data processing and analysis being carried out in accordance with the passage of time in the real world, meaning that delays are minimized.

[0362] A "warning" refers to a notification or message provided by a system to inform the user of potential dangers or situations that require attention.

[0363] This invention is an advanced digital protection system that combines fraud detection and sentiment recognition. The server automatically acquires data on the latest fraud patterns and techniques from an information network. Based on the collected information, the server builds a fraud detection model using programming languages ​​such as Python and libraries such as Scikit-learn and TensorFlow. This model learns patterns to identify fraudulent activities and analyzes user data. Furthermore, the server prepares the data necessary for sentiment analysis devices and provides a foundation for identifying the user's emotional state.

[0364] The terminal utilizes fraud detection models and sentiment analysis devices provided by the server. With the user's permission, the terminal monitors communication and voice data in real time and analyzes signs of fraud. The sentiment engine implemented on the terminal analyzes voice tone, text content, and behavioral patterns to identify the user's emotional state. Specific software used includes NLTK and Hugging Face Transformers.

[0365] For example, when a user receives an email requesting an urgent account information update, the device immediately analyzes the email's content and detects that it is likely a scam. Simultaneously, the emotion engine may detect an increase in heart rate and determine that the user is feeling anxious. In such cases, the device displays an emotion-sensitive warning message such as, "This email may be a scam. Please remain calm and contact the appropriate department." Examples of these prompts may include, "Please describe the characteristics of a scam email," or "What can help the user feel at ease?"

[0366] Users can receive warnings and advice from the system and provide feedback. This feedback is sent to the server and used to improve the accuracy of the fraud detection model and sentiment analysis device. This allows the system to continuously evolve and provide users with a safer and more comfortable digital experience.

[0367] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0368] Step 1:

[0369] The server retrieves data on the latest fraud patterns from its information network. It uses a list of URLs from news sites and specialized databases as input, collecting information using web scraping techniques. The output is a dataset containing characteristics and related information of fraudulent methods. This dataset is used in the subsequent model generation process.

[0370] Step 2:

[0371] The server builds a generative AI model based on the data collected in Step 1. It receives a dataset of fraud features as input and trains the model using machine learning algorithms with Scikit-learn or TensorFlow. The output is a classification model for fraud detection. This model is used to distinguish between fraud and normal behavior.

[0372] Step 3:

[0373] The server prepares data for the emotion analysis device. It collects emotion label information based on speech and text as input, and constructs a dataset using NLTK and Hugging Face Transformers. The output is a dataset that serves as a baseline for identifying the user's emotional state. This dataset is used for emotion analysis on the terminal.

[0374] Step 4:

[0375] The terminal receives a fraud detection model and sentiment analysis device provided by the server and executes them on the user's device. It monitors the user's communication data and voice data as input. The output is real-time fraud detection results and identification of emotional states. Specifically, it analyzes emails and call content to immediately identify signs of fraud and changes in emotion.

[0376] Step 5:

[0377] The device generates and displays a warning message to the user based on detected fraud signs and emotional state. It uses the results of fraud model detection and sentiment analysis as input. The output is a customized warning message tailored to the user's situation, such as, "This may be a scam. Please remain calm."

[0378] Step 6:

[0379] Users receive warnings from their devices, take necessary actions, and provide feedback based on their experience. Input consists of the warning content and the user's personal response experience, which are used to generate feedback. Output is improvement suggestions and experience evaluations sent to the server. This feedback is used for the continuous improvement of the system.

[0380] (Application Example 2)

[0381] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0382] In modern electronic financial transactions, fraudulent activities are becoming increasingly sophisticated, making it difficult for users to trade online with confidence. Furthermore, users who encounter signs of fraud often experience anxiety and stress, which can impair their ability to make rational decisions. In this context, there is a need not only to quickly detect signs of fraud but also to provide appropriate warnings and support that take into account the user's emotional state.

[0383] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[0384] In this invention, the server includes means for collecting information on the latest fraudulent methods from the internet, means for generating a model for detecting fraudulent activity using a generative model based on the collected information, and means for analyzing user information using the model to detect signs of fraud. This makes it possible to analyze the user's communication information in real time and immediately issue a warning, taking into account the emotional state, if there is a possibility of fraud.

[0385] "Fraudulent practices" are means or techniques used to deceive users and extort money or personal information from them.

[0386] A "generative model" is a method for generating algorithms to detect fraudulent activity using collected data.

[0387] "Emotional state" refers to the user's psychological and physiological emotional state, which includes anxiety, stress, tension, etc.

[0388] "Adjusting the wording of warnings" means changing the content and tone of warning messages according to the user's emotional state.

[0389] "Communication information" refers to data that users send and receive through electronic devices, and includes voice, text, and other digital information.

[0390] "Real-time analysis" means processing the data almost instantly after it is acquired and obtaining the results.

[0391] The system for implementing this invention is intended to consist of a server and terminals, and to operate in coordination with each other.

[0392] The server is responsible for collecting information on the latest fraud techniques from the internet. This is done through web crawling technologies and APIs, and stored in a database as needed. Based on this information, the server uses AI generative models (e.g., custom models using TensorFlow) to generate analytical models for detecting fraudulent activity. For analyzing emotional states, it uses speech analysis libraries (e.g., Google Speech-to-Text API).

[0393] The terminal retrieves the generative model from the server and analyzes the user's communication information (voice, text, etc.) in real time. If signs of fraud are detected through this analysis, the emotional state is evaluated. For example, changes in voice or behavioral patterns are interpreted as emotional states. Based on this emotional state, the terminal adjusts the content and tone of the warning message and presents it to the user. This helps the user to calmly assess the situation.

[0394] Users can submit feedback on warnings provided from their devices. This feedback is returned to the server and used to improve the fraud detection and sentiment analysis models. By collecting and applying feedback, the system is continuously updated, enabling more sophisticated fraud prevention measures.

[0395] As a concrete example, when a user attempts to purchase an expensive item from a new online shop, the device analyzes the transaction and, if it determines there is a high risk of fraud, checks the user's emotional state. For instance, if it detects signs of anxiety and an elevated heart rate, the device displays a gentle message such as, "This transaction carries a risk of fraud. Further details are recommended."

[0396] An example of a prompt message is: "A user is attempting to make a large online payment. If there are signs of fraud, how should a warning be issued? Also, design an effective, emotion-based warning message."

[0397] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0398] Step 1:

[0399] The server collects information about fraudulent methods from the internet. Using web crawling technology and APIs, it retrieves the latest fraud-related data and stores it in a database. This prepares the information in a format that can be used to generate fraud models.

[0400] Step 2:

[0401] The server creates a fraud detection model using a generative AI model (e.g., TensorFlow) based on the collected data. The latest fraud information is used as input, and the detection model is obtained as output. The generated model is then used to analyze user data.

[0402] Step 3:

[0403] The device retrieves a fraud detection model from the server and begins real-time analysis of the user's communication information (voice, text, etc.). It analyzes the user's communication data as input and outputs a detection result if there are signs of fraud.

[0404] Step 4:

[0405] The device evaluates the user's emotional state in response to detected signs of fraud. Using a speech analysis library (e.g., Google Speech-to-Text API), it analyzes the emotional state using voice tone and behavioral patterns as input. Based on this, changes in emotion are output.

[0406] Step 5:

[0407] The device adjusts warning messages based on the analyzed emotional state. It receives the emotional state and fraud detection results as input and generates and displays a warning with appropriate content and tone to the user.

[0408] Step 6:

[0409] The user reviews the warning message displayed on the device and provides feedback as needed. The user's feedback is sent to the server for system improvement. The user's response is received as input, and feedback information is returned to the server.

[0410] Step 7:

[0411] The server updates its fraud detection and sentiment analysis models based on user feedback. Feedback information is provided as input, which adjusts the models, resulting in improved models as output. This cycle allows the system to continuously improve.

[0412] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0413] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0414] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.

[0415] [Third Embodiment]

[0416] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.

[0417] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0418] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0419] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.

[0420] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0421] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0422] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0423] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0424] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0425] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0426] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0427] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".

[0428] The system of this invention is integrated into the user's digital communication environment and provides a method for detecting and responding to fraud threats in real time. This system operates with a server and terminal working together to collect the latest fraud techniques and generate a detection model based on that information. It then analyzes communication content on the user's terminal and immediately alerts the user if signs of fraud are detected.

[0429] Server Role

[0430] The server collects fraud-related data from various sources on the internet. This includes samples of phishing emails and summaries of newly reported fraud techniques. The collected data allows the generative model to be kept constantly up-to-date. The server analyzes this data and trains machine learning models to generate models for detecting fraudulent activities with high accuracy.

[0431] Terminal role

[0432] The client program installed on the device monitors emails, messages, and call content with the user's consent. Based on a fraud detection model provided by the server, this program analyzes communication content and detects signs of fraud. Specifically, if it contains phishing links, malicious requests, or is determined to be communication from a suspicious sender, the device will display a warning. This warning includes specific instructions such as not opening the email or message or clicking on any links.

[0433] User experience

[0434] Users can view warnings displayed on their devices and take appropriate action based on their content. For example, they can delete emails displaying warnings or promptly hang up suspicious phone calls. Furthermore, the system receives feedback from users, which is used in the next model update. This improves the user experience and allows the system to evolve to respond quickly to new fraud trends.

[0435] For example, when a user receives an email stating, "Your account has been hacked," the device detects that this email is a sign of fraud. The system analyzes the email in real time, compares it to a database of fraudulent emails, and if it is deemed high-risk, a warning such as, "This email may be fraudulent. Do not open the attached link," is displayed. By following this advice and deleting the email, the user can prevent becoming a victim of fraud.

[0436] Thus, the system of the present invention provides users with protection from fraud and creates an environment in which they can use the digital society with peace of mind.

[0437] The following describes the processing flow.

[0438] Step 1:

[0439] The server regularly scans publicly available databases and related information sources on the internet to collect new fraud techniques and specific examples of them. This collection includes the use of web scraping techniques and external APIs.

[0440] Step 2:

[0441] The server analyzes the latest fraud-related data it has collected and uses it to train a generative model. This training process uses machine learning algorithms and aims to build a highly accurate model for detecting signs of fraud.

[0442] Step 3:

[0443] The device receives fraud detection models from the server and monitors the user's communication data (emails, messages, call content) in real time. This data is only collected after obtaining the user's permission.

[0444] Step 4:

[0445] The device analyzes user data based on a detection model to look for signs of fraud. This analysis uses text mining and speech recognition technologies to identify suspicious links, requests, and other elements.

[0446] Step 5:

[0447] If the device detects signs of fraud, it will immediately display a warning to the user. The warning message will specifically indicate the content of the relevant communication and include instructions on how the user should respond.

[0448] Step 6:

[0449] Users can review warnings from their devices and take appropriate action if necessary. This includes deleting the email, not opening any related links, or not replying to the sender.

[0450] Step 7:

[0451] The system collects user actions and responses to warnings as feedback and sends it to the server. This feedback is used for the next model training, contributing to improving the system's accuracy.

[0452] (Example 1)

[0453] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[0454] In today's world, where internet-based communication is widespread, fraudulent activities are becoming more sophisticated and diverse. Traditional methods are insufficient to respond quickly to new fraudulent techniques, increasing the likelihood of users becoming victims. Furthermore, processes for maintaining and updating the accuracy of models used to detect fraudulent activity are not yet fully established. Therefore, new methods are needed to effectively protect users from fraud.

[0455] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0456] In this invention, the server includes means for collecting information on fraudulent methods in digital communications from a communication network, means for generating a logical structure for detecting fraudulent activity using a machine learning model generated based on the collected information, and means for analyzing user information using the logical structure to detect signs of fraudulent activity. This makes it possible to respond quickly to the latest fraudulent methods and effectively protect users from fraud.

[0457] "Digital communication" refers to sending and receiving information via the internet or other electronic communication technologies.

[0458] "Fraudulent methods" refer to dishonest methods or techniques used to deceive others.

[0459] "Communication network" refers to the entire infrastructure for transmitting information, namely the internet and other digital networks.

[0460] A "machine learning model" refers to a mathematical algorithm that learns from data and makes predictions and decisions about future instances.

[0461] A "logical structure" refers to a combination of information and processes used to achieve a certain objective, and the framework for analyzing data and deriving meaningful conclusions based on that structure.

[0462] "User" refers to an individual or legal entity that uses this system.

[0463] "Misconduct" refers to unacceptable actions that use means that violate laws or ethics.

[0464] "Evaluation" refers to opinions and feedback provided by users, and it provides information that contributes to improving the system.

[0465] "Immediate" refers to an action being performed within a very short timeframe, meaning there is virtually no time delay.

[0466] In this embodiment of the invention, a system is constructed to protect users from fraudulent activities by having a server and a terminal cooperate.

[0467] The server collects information about fraudulent practices from various data sources on the communication network. This includes publicly available data from websites, social media, and news platforms. The collected information is filtered and cleaned using data analysis software and then fed into machine learning algorithms. Based on this information, the server generates constantly updated machine learning models and uses these models to develop highly accurate fraud detection logic. This model is delivered to the device via a cloud storage service.

[0468] The terminal has a client program installed that monitors communication data with the user's permission. The terminal analyzes emails and messages in real time and evaluates the data based on a fraud detection model provided by the server. For example, if an email received contains a typical fraudulent phrase such as "Your account is at risk," the terminal will notify the user to warn them.

[0469] A concrete example of a prompt message would be, "What are effective sources of information for collecting data on new phishing techniques and updating the fraud detection model?" This serves as input for the system to constantly optimize the model based on the latest data.

[0470] Users can review warnings displayed on their devices and take measures such as deleting potentially fraudulent emails based on the information provided. This allows users to use digital communications with peace of mind. A feedback function sends user information to the server, which is then used to improve the system in the future. In this way, the system provides concrete solutions to efficiently protect users from fraud.

[0471] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0472] Step 1:

[0473] The server collects data on fraudulent methods from various sources on the communication network. Specifically, the server extracts information using relevant keywords from news sites, forums, social media, etc. The input to this process is a list of keywords related to fraud, and the output is text data about fraudulent methods. Web scraping techniques are used for data collection.

[0474] Step 2:

[0475] The server analyzes, filters, and cleans the collected data. The input is the collected, raw fraud-related data, and the output is a clean, structured dataset. Data analysis tools are used to remove noise and normalize the data, preparing it for machine learning.

[0476] Step 3:

[0477] The server trains a machine learning model based on the cleaned data. The input is a filtered dataset, and the output is a fraud detection model. Generative AI modeling techniques are used to train the model, learning diverse fraud patterns and building a highly accurate logical structure.

[0478] Step 4:

[0479] The server delivers the latest fraud detection model to the device via cloud storage. The input is the trained fraud detection model, and the output is the model data stored on the device. Delivery is performed regularly to ensure that the latest model is always available on the device.

[0480] Step 5:

[0481] The terminal's client program monitors and analyzes message data in real time. The input is the user's communication content (e.g., emails or messages), and the output is a judgment regarding detected signs of fraud. Based on a model delivered from the server, the terminal analyzes the communication content and detects signs of fraud.

[0482] Step 6:

[0483] The device will warn the user if signs of fraud are detected. The input is communication data that has been determined to be potentially fraudulent, and the output is a warning message to the user. Specifically, it will display a warning message in a pop-up to alert the user. For example, it may display something like, "This email may be fraudulent, so do not open the link."

[0484] Step 7:

[0485] Users take fraud prevention measures based on warnings from their devices. The input is the warning message from the device, and the output is the user's response. Examples include deleting the email in question or not clicking on suspicious links. Users can also report their decisions to the system using the feedback function.

[0486] In this way, throughout each step, the server and terminal work closely together to implement a process that protects users from fraudulent activities.

[0487] (Application Example 1)

[0488] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[0489] In today's digital communication environment, fraudulent methods are becoming increasingly sophisticated, making it difficult for users to deal with these threats. In particular, detecting signs of fraud in real time and providing appropriate warnings before users become victims is a critical challenge. There is a need to provide rapid and effective defenses against such fraudulent activities.

[0490] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0491] In this invention, the server includes means for collecting information on the latest fraudulent methods from information sources, means for generating a model for detecting fraudulent activity using a generative model based on the collected information, and means for analyzing user information using the model to detect signs of fraud. This makes it possible to monitor the user's communication data in real time and to quickly warn in the event of potential fraud.

[0492] "Information source" refers to a data provider used to collect information about fraudulent methods.

[0493] A "generative model" is a mechanism for creating predictive algorithms to detect fraudulent activity based on collected data.

[0494] "User" refers to an individual or organization that uses the fraud detection system.

[0495] "Signs of fraud" are specific patterns or indicators that suggest fraudulent activity may be taking place.

[0496] A "warning" is a notification that informs users of the possibility of fraud and serves as a cautionary tale.

[0497] "Communication data" refers to information that users send and receive in digital communications, such as emails, messages, and phone calls.

[0498] "Mobile device" refers to electronic devices such as smartphones and tablets that users can carry with them.

[0499] "Head-mounted display devices" refer to devices such as smart glasses and head-mounted displays that are worn and used by the user.

[0500] The system realizing this invention involves a server and a terminal working together to detect and warn of signs of fraud in real time. The server collects information on fraudulent methods from various sources and uses this information to generate an advanced predictive model for detecting fraudulent activity using a generative model. The generated model is transmitted to the terminal. On the terminal, the user's communication data is monitored in real time, and if signs of fraud are found, a warning is issued quickly. The warning is displayed on the user's mobile device or a head-mounted display device.

[0501] Specifically, the server uses Python or a similar programming environment to analyze diverse data sources on the internet and learn signs of phishing emails and other fraudulent activities. On the terminal side, the collected models are used to analyze emails and messages contained in communications and assess the fraud risk. This allows users to instantly recognize emails containing suspicious links and prevent fraud before it happens.

[0502] For example, when a user receives a message stating, "Your account has been accessed without authorization," the device analyzes this message in real time. If a high risk of fraud is detected, it immediately displays a warning such as, "This message may be a scam." This allows the user to act safely without clicking on any links.

[0503] Examples of prompt messages include the following:

[0504] "Detect whether the following message is a fraud: 'You've won a free vacation. Click here to claim your prize.'"

[0505] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0506] Step 1:

[0507] The server collects data on fraudulent methods from internet sources. Inputs include phishing emails, URLs of fraudulent websites, and summaries of reported fraud cases. This information is collected and stored in a database to prepare the foundational data for generating highly accurate fraud detection models. The output is updates to the fraudulent methods database.

[0508] Step 2:

[0509] The server trains a generative AI model based on the collected data. The input is the fraud-related data collected in Step 1. This is fed into a machine learning algorithm to generate a model for detecting fraudulent activity. During this process, data processing steps such as feature extraction and data normalization are performed. The output is the newly trained fraud detection model.

[0510] Step 3:

[0511] The server sends the trained fraud detection model to the terminal. The input is the fraud detection model generated in step 2. The output is the state change of the terminal, which has received the model and is preparing for analysis.

[0512] Step 4:

[0513] The device monitors the user's communication data in real time using the received fraud detection model. Inputs include emails, messages, and call content sent and received by the user. This data is analyzed in real time to detect signs of fraud. The output is information about the detected signs of fraud.

[0514] Step 5:

[0515] The device immediately displays a warning to the user if signs of fraud are detected. The input is the fraud indicator data obtained in step 4. Based on this data, a warning message is generated to help the user take appropriate action and displayed on the mobile device or head-mounted display device. The output is the warning displayed to the user and the corresponding user action.

[0516] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0517] This invention's system incorporates an emotion engine that recognizes user emotions in addition to a fraud detection function. This allows the system to analyze the user's emotional state based on the detected signs of fraud while the user is using digital communication, and then provide an appropriate response.

[0518] Server Role

[0519] The server collects the latest fraud information from the internet and generates models to detect fraudulent activities. In addition, it prepares the data necessary for the emotion engine and provides a foundation for analyzing the user's emotional state.

[0520] Terminal role

[0521] The device operates using a fraud detection model and sentiment engine provided by the server. With the user's permission, it monitors communication data, voice, and data related to the user's emotions. This data is analyzed in real time to look for signs of fraud.

[0522] The emotion engine identifies the user's emotional state from factors such as voice tone, text content, and behavioral patterns. If fraud is detected and it is determined that the user is experiencing anxiety or stress as a result, the system takes this into account and provides the user with an appropriate warning.

[0523] User feedback and response

[0524] Users can receive emotionally-sensitive advice through warning messages on their devices. For example, if a user is feeling stressed, the warning may be delivered in a gentle tone or display additional support information (such as who they can talk to).

[0525] Specific example

[0526] For example, if a user receives an email requesting an urgent account information update, the device analyzes the email and determines that it is likely a scam. The emotion engine may simultaneously detect that the user's heart rate has increased and they are feeling anxious while reading the email. In this case, the device displays a warning message tailored to the user's emotional state, such as, "This email may be a scam. Please remain calm and contact our support center."

[0527] Furthermore, user feedback is sent to the server and used to improve the fraud detection model and sentiment engine. This allows the system to continuously improve the user experience and strengthen protection against fraud.

[0528] The introduction of this system will reduce the risk of fraud for users, allowing them to continue using the digital world with peace of mind.

[0529] The following describes the processing flow.

[0530] Step 1:

[0531] The server collects data on the latest fraud techniques from publicly available databases on the internet and related sources. This information includes phishing email samples and new fraud methods.

[0532] Step 2:

[0533] The server analyzes the collected data and builds a generative model to detect fraudulent activity. This model is trained using machine learning algorithms to improve its ability to identify new signs of fraud.

[0534] Step 3:

[0535] The server uses an emotion engine to prepare training data for emotion recognition and lay the foundation for understanding various human emotional states.

[0536] Step 4:

[0537] The device receives fraud detection models and sentiment engines provided by the server and monitors the user's communication data in real time. This data includes emails, messages, and voice data.

[0538] Step 5:

[0539] The device uses a fraud detection model to analyze the user's communication data and detect signs of fraud. If a fraudulent email or suspicious link is detected, the information is recorded in detail.

[0540] Step 6:

[0541] The device's emotion engine analyzes the user's emotions from their voice tone and text content. For example, it can determine whether a user is feeling anxious while reading an email.

[0542] Step 7:

[0543] The device will display an emotionally appropriate warning to the user if signs of fraud are detected and the user is feeling anxious. This warning will include appropriate countermeasures and support information.

[0544] Step 8:

[0545] Users review the displayed warnings and select safe actions as needed. For example, they might delete emails suspected of being fraudulent.

[0546] Step 9:

[0547] The user's actions and responses to warnings are sent to the server as feedback. This feedback is used to further improve the generative model and sentiment engine.

[0548] (Example 2)

[0549] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[0550] Traditional fraud detection systems focus on detecting signs of fraud, but they are unable to respond in a way that aligns with the emotional state of users affected by detected fraud. As a result, users' stress and anxiety remain unresolved, and the optimal response is not provided.

[0551] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0552] In this invention, the server includes means for collecting information on the latest fraudulent methods from a communication network, means for generating a model for identifying fraudulent activities using a generative model based on the collected information, and means for identifying the user's emotional state using an emotion analysis device. This makes it possible to provide appropriate warnings and responses according to the user's emotional state, enabling the user to use the digital environment with peace of mind.

[0553] "Communication network" refers to the infrastructure and technologies used to send and receive information, and in particular includes the internet and other digital networks.

[0554] A "generative model" refers to a machine learning model that learns patterns from data and is built to make predictions and classifications on new data.

[0555] "Fraudulent activity" refers to any action or means taken to deceive others with dishonesty or malicious intent.

[0556] An "emotion analysis device" refers to a system that includes technologies and devices that analyze voice, text, behavioral patterns, etc., in order to identify a user's emotional state.

[0557] "Users" refers to individuals or organizations that use the system to provide information or receive services.

[0558] "Real-time" refers to data processing and analysis being carried out in accordance with the passage of time in the real world, meaning that delays are minimized.

[0559] A "warning" refers to a notification or message provided by a system to inform the user of potential dangers or situations that require attention.

[0560] This invention is an advanced digital protection system that combines fraud detection and sentiment recognition. The server automatically acquires data on the latest fraud patterns and techniques from an information network. Based on the collected information, the server builds a fraud detection model using programming languages ​​such as Python and libraries such as Scikit-learn and TensorFlow. This model learns patterns to identify fraudulent activities and analyzes user data. Furthermore, the server prepares the data necessary for sentiment analysis devices and provides a foundation for identifying the user's emotional state.

[0561] The terminal utilizes fraud detection models and sentiment analysis devices provided by the server. With the user's permission, the terminal monitors communication and voice data in real time and analyzes signs of fraud. The sentiment engine implemented on the terminal analyzes voice tone, text content, and behavioral patterns to identify the user's emotional state. Specific software used includes NLTK and Hugging Face Transformers.

[0562] For example, when a user receives an email requesting an urgent account information update, the device immediately analyzes the email's content and detects that it is likely a scam. Simultaneously, the emotion engine may detect an increase in heart rate and determine that the user is feeling anxious. In such cases, the device displays an emotion-sensitive warning message such as, "This email may be a scam. Please remain calm and contact the appropriate department." Examples of these prompts may include, "Please describe the characteristics of a scam email," or "What can help the user feel at ease?"

[0563] Users can receive warnings and advice from the system and provide feedback. This feedback is sent to the server and used to improve the accuracy of the fraud detection model and sentiment analysis device. This allows the system to continuously evolve and provide users with a safer and more comfortable digital experience.

[0564] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0565] Step 1:

[0566] The server retrieves data on the latest fraud patterns from its information network. It uses a list of URLs from news sites and specialized databases as input, collecting information using web scraping techniques. The output is a dataset containing characteristics and related information of fraudulent methods. This dataset is used in the subsequent model generation process.

[0567] Step 2:

[0568] The server builds a generative AI model based on the data collected in Step 1. It receives a dataset of fraud features as input and trains the model using machine learning algorithms with Scikit-learn or TensorFlow. The output is a classification model for fraud detection. This model is used to distinguish between fraud and normal behavior.

[0569] Step 3:

[0570] The server prepares data for the emotion analysis device. It collects emotion label information based on speech and text as input, and constructs a dataset using NLTK and Hugging Face Transformers. The output is a dataset that serves as a baseline for identifying the user's emotional state. This dataset is used for emotion analysis on the terminal.

[0571] Step 4:

[0572] The terminal receives a fraud detection model and sentiment analysis device provided by the server and executes them on the user's device. It monitors the user's communication data and voice data as input. The output is real-time fraud detection results and identification of emotional states. Specifically, it analyzes emails and call content to immediately identify signs of fraud and changes in emotion.

[0573] Step 5:

[0574] The device generates and displays a warning message to the user based on detected fraud signs and emotional state. It uses the results of fraud model detection and sentiment analysis as input. The output is a customized warning message tailored to the user's situation, such as, "This may be a scam. Please remain calm."

[0575] Step 6:

[0576] Users receive warnings from their devices, take necessary actions, and provide feedback based on their experience. Input consists of the warning content and the user's personal response experience, which are used to generate feedback. Output is improvement suggestions and experience evaluations sent to the server. This feedback is used for the continuous improvement of the system.

[0577] (Application Example 2)

[0578] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[0579] In modern electronic financial transactions, fraudulent activities are becoming increasingly sophisticated, making it difficult for users to trade online with confidence. Furthermore, users who encounter signs of fraud often experience anxiety and stress, which can impair their ability to make rational decisions. In this context, there is a need not only to quickly detect signs of fraud but also to provide appropriate warnings and support that take into account the user's emotional state.

[0580] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[0581] In this invention, the server includes means for collecting information on the latest fraudulent methods from the internet, means for generating a model for detecting fraudulent activity using a generative model based on the collected information, and means for analyzing user information using the model to detect signs of fraud. This makes it possible to analyze the user's communication information in real time and immediately issue a warning, taking into account the emotional state, if there is a possibility of fraud.

[0582] "Fraudulent practices" are means or techniques used to deceive users and extort money or personal information from them.

[0583] A "generative model" is a method for generating algorithms to detect fraudulent activity using collected data.

[0584] "Emotional state" refers to the user's psychological and physiological emotional state, which includes anxiety, stress, tension, etc.

[0585] "Adjusting the wording of warnings" means changing the content and tone of warning messages according to the user's emotional state.

[0586] "Communication information" refers to data that users send and receive through electronic devices, and includes voice, text, and other digital information.

[0587] "Real-time analysis" means processing the data almost instantly after it is acquired and obtaining the results.

[0588] The system for implementing this invention is intended to consist of a server and terminals, and to operate in coordination with each other.

[0589] The server is responsible for collecting information on the latest fraud techniques from the internet. This is done through web crawling technologies and APIs, and stored in a database as needed. Based on this information, the server uses AI generative models (e.g., custom models using TensorFlow) to generate analytical models for detecting fraudulent activity. For analyzing emotional states, it uses speech analysis libraries (e.g., Google Speech-to-Text API).

[0590] The terminal retrieves the generative model from the server and analyzes the user's communication information (voice, text, etc.) in real time. If signs of fraud are detected through this analysis, the emotional state is evaluated. For example, changes in voice or behavioral patterns are interpreted as emotional states. Based on this emotional state, the terminal adjusts the content and tone of the warning message and presents it to the user. This helps the user to calmly assess the situation.

[0591] Users can submit feedback on warnings provided from their devices. This feedback is returned to the server and used to improve the fraud detection and sentiment analysis models. By collecting and applying feedback, the system is continuously updated, enabling more sophisticated fraud prevention measures.

[0592] As a concrete example, when a user attempts to purchase an expensive item from a new online shop, the device analyzes the transaction and, if it determines there is a high risk of fraud, checks the user's emotional state. For instance, if it detects signs of anxiety and an elevated heart rate, the device displays a gentle message such as, "This transaction carries a risk of fraud. Further details are recommended."

[0593] An example of a prompt message is: "A user is attempting to make a large online payment. If there are signs of fraud, how should a warning be issued? Also, design an effective, emotion-based warning message."

[0594] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0595] Step 1:

[0596] The server collects information about fraudulent methods from the internet. Using web crawling technology and APIs, it retrieves the latest fraud-related data and stores it in a database. This prepares the information in a format that can be used to generate fraud models.

[0597] Step 2:

[0598] The server creates a fraud detection model using a generative AI model (e.g., TensorFlow) based on the collected data. The latest fraud information is used as input, and the detection model is obtained as output. The generated model is then used to analyze user data.

[0599] Step 3:

[0600] The device retrieves a fraud detection model from the server and begins real-time analysis of the user's communication information (voice, text, etc.). It analyzes the user's communication data as input and outputs a detection result if there are signs of fraud.

[0601] Step 4:

[0602] The device evaluates the user's emotional state in response to detected signs of fraud. Using a speech analysis library (e.g., Google Speech-to-Text API), it analyzes the emotional state using voice tone and behavioral patterns as input. Based on this, changes in emotion are output.

[0603] Step 5:

[0604] The device adjusts warning messages based on the analyzed emotional state. It receives the emotional state and fraud detection results as input and generates and displays a warning with appropriate content and tone to the user.

[0605] Step 6:

[0606] The user reviews the warning message displayed on the device and provides feedback as needed. The user's feedback is sent to the server for system improvement. The user's response is received as input, and feedback information is returned to the server.

[0607] Step 7:

[0608] The server updates its fraud detection and sentiment analysis models based on user feedback. Feedback information is provided as input, which adjusts the models, resulting in improved models as output. This cycle allows the system to continuously improve.

[0609] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0610] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0611] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.

[0612] [Fourth Embodiment]

[0613] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.

[0614] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[0615] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0616] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.

[0617] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0618] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0619] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0620] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.

[0621] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0622] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0623] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0624] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0625] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[0626] The system of this invention is integrated into the user's digital communication environment and provides a method for detecting and responding to fraud threats in real time. This system operates with a server and terminal working together to collect the latest fraud techniques and generate a detection model based on that information. It then analyzes communication content on the user's terminal and immediately alerts the user if signs of fraud are detected.

[0627] Server Role

[0628] The server collects fraud-related data from various sources on the internet. This includes samples of phishing emails and summaries of newly reported fraud techniques. The collected data allows the generative model to be kept constantly up-to-date. The server analyzes this data and trains machine learning models to generate models for detecting fraudulent activities with high accuracy.

[0629] Terminal role

[0630] The client program installed on the device monitors emails, messages, and call content with the user's consent. Based on a fraud detection model provided by the server, this program analyzes communication content and detects signs of fraud. Specifically, if it contains phishing links, malicious requests, or is determined to be communication from a suspicious sender, the device will display a warning. This warning includes specific instructions such as not opening the email or message or clicking on any links.

[0631] User experience

[0632] Users can view warnings displayed on their devices and take appropriate action based on their content. For example, they can delete emails displaying warnings or promptly hang up suspicious phone calls. Furthermore, the system receives feedback from users, which is used in the next model update. This improves the user experience and allows the system to evolve to respond quickly to new fraud trends.

[0633] For example, when a user receives an email stating, "Your account has been hacked," the device detects that this email is a sign of fraud. The system analyzes the email in real time, compares it to a database of fraudulent emails, and if it is deemed high-risk, a warning such as, "This email may be fraudulent. Do not open the attached link," is displayed. By following this advice and deleting the email, the user can prevent becoming a victim of fraud.

[0634] Thus, the system of the present invention provides users with protection from fraud and creates an environment in which they can use the digital society with peace of mind.

[0635] The following describes the processing flow.

[0636] Step 1:

[0637] The server regularly scans publicly available databases and related information sources on the internet to collect new fraud techniques and specific examples of them. This collection includes the use of web scraping techniques and external APIs.

[0638] Step 2:

[0639] The server analyzes the latest fraud-related data it has collected and uses it to train a generative model. This training process uses machine learning algorithms and aims to build a highly accurate model for detecting signs of fraud.

[0640] Step 3:

[0641] The device receives fraud detection models from the server and monitors the user's communication data (emails, messages, call content) in real time. This data is only collected after obtaining the user's permission.

[0642] Step 4:

[0643] The device analyzes user data based on a detection model to look for signs of fraud. This analysis uses text mining and speech recognition technologies to identify suspicious links, requests, and other elements.

[0644] Step 5:

[0645] If the device detects signs of fraud, it will immediately display a warning to the user. The warning message will specifically indicate the content of the relevant communication and include instructions on how the user should respond.

[0646] Step 6:

[0647] Users can review warnings from their devices and take appropriate action if necessary. This includes deleting the email, not opening any related links, or not replying to the sender.

[0648] Step 7:

[0649] The system collects user actions and responses to warnings as feedback and sends it to the server. This feedback is used for the next model training, contributing to improving the system's accuracy.

[0650] (Example 1)

[0651] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[0652] In today's world, where internet-based communication is widespread, fraudulent activities are becoming more sophisticated and diverse. Traditional methods are insufficient to respond quickly to new fraudulent techniques, increasing the likelihood of users becoming victims. Furthermore, processes for maintaining and updating the accuracy of models used to detect fraudulent activity are not yet fully established. Therefore, new methods are needed to effectively protect users from fraud.

[0653] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0654] In this invention, the server includes means for collecting information on fraudulent methods in digital communications from a communication network, means for generating a logical structure for detecting fraudulent activity using a machine learning model generated based on the collected information, and means for analyzing user information using the logical structure to detect signs of fraudulent activity. This makes it possible to respond quickly to the latest fraudulent methods and effectively protect users from fraud.

[0655] "Digital communication" refers to sending and receiving information via the internet or other electronic communication technologies.

[0656] "Fraudulent methods" refer to dishonest methods or techniques used to deceive others.

[0657] "Communication network" refers to the entire infrastructure for transmitting information, namely the internet and other digital networks.

[0658] A "machine learning model" refers to a mathematical algorithm that learns from data and makes predictions and decisions about future instances.

[0659] A "logical structure" refers to a combination of information and processes used to achieve a certain objective, and the framework for analyzing data and deriving meaningful conclusions based on that structure.

[0660] "User" refers to an individual or legal entity that uses this system.

[0661] "Misconduct" refers to unacceptable actions that use means that violate laws or ethics.

[0662] "Evaluation" refers to opinions and feedback provided by users, and it provides information that contributes to improving the system.

[0663] "Immediate" refers to an action being performed within a very short timeframe, meaning there is virtually no time delay.

[0664] In this embodiment of the invention, a system is constructed to protect users from fraudulent activities by having a server and a terminal cooperate.

[0665] The server collects information about fraudulent practices from various data sources on the communication network. This includes publicly available data from websites, social media, and news platforms. The collected information is filtered and cleaned using data analysis software and then fed into machine learning algorithms. Based on this information, the server generates constantly updated machine learning models and uses these models to develop highly accurate fraud detection logic. This model is delivered to the device via a cloud storage service.

[0666] The terminal has a client program installed that monitors communication data with the user's permission. The terminal analyzes emails and messages in real time and evaluates the data based on a fraud detection model provided by the server. For example, if an email received contains a typical fraudulent phrase such as "Your account is at risk," the terminal will notify the user to warn them.

[0667] A concrete example of a prompt message would be, "What are effective sources of information for collecting data on new phishing techniques and updating the fraud detection model?" This serves as input for the system to constantly optimize the model based on the latest data.

[0668] Users can review warnings displayed on their devices and take measures such as deleting potentially fraudulent emails based on the information provided. This allows users to use digital communications with peace of mind. A feedback function sends user information to the server, which is then used to improve the system in the future. In this way, the system provides concrete solutions to efficiently protect users from fraud.

[0669] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0670] Step 1:

[0671] The server collects data on fraudulent methods from various sources on the communication network. Specifically, the server extracts information using relevant keywords from news sites, forums, social media, etc. The input to this process is a list of keywords related to fraud, and the output is text data about fraudulent methods. Web scraping techniques are used for data collection.

[0672] Step 2:

[0673] The server analyzes, filters, and cleans the collected data. The input is the collected, raw fraud-related data, and the output is a clean, structured dataset. Data analysis tools are used to remove noise and normalize the data, preparing it for machine learning.

[0674] Step 3:

[0675] The server trains a machine learning model based on the cleaned data. The input is a filtered dataset, and the output is a fraud detection model. Generative AI modeling techniques are used to train the model, learning diverse fraud patterns and building a highly accurate logical structure.

[0676] Step 4:

[0677] The server delivers the latest fraud detection model to the device via cloud storage. The input is the trained fraud detection model, and the output is the model data stored on the device. Delivery is performed regularly to ensure that the latest model is always available on the device.

[0678] Step 5:

[0679] The terminal's client program monitors and analyzes message data in real time. The input is the user's communication content (e.g., emails or messages), and the output is a judgment regarding detected signs of fraud. Based on a model delivered from the server, the terminal analyzes the communication content and detects signs of fraud.

[0680] Step 6:

[0681] The device will warn the user if signs of fraud are detected. The input is communication data that has been determined to be potentially fraudulent, and the output is a warning message to the user. Specifically, it will display a warning message in a pop-up to alert the user. For example, it may display something like, "This email may be fraudulent, so do not open the link."

[0682] Step 7:

[0683] Users take fraud prevention measures based on warnings from their devices. The input is the warning message from the device, and the output is the user's response. Examples include deleting the email in question or not clicking on suspicious links. Users can also report their decisions to the system using the feedback function.

[0684] In this way, throughout each step, the server and terminal work closely together to implement a process that protects users from fraudulent activities.

[0685] (Application Example 1)

[0686] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[0687] In today's digital communication environment, fraudulent methods are becoming increasingly sophisticated, making it difficult for users to deal with these threats. In particular, detecting signs of fraud in real time and providing appropriate warnings before users become victims is a critical challenge. There is a need to provide rapid and effective defenses against such fraudulent activities.

[0688] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0689] In this invention, the server includes means for collecting information on the latest fraudulent methods from information sources, means for generating a model for detecting fraudulent activity using a generative model based on the collected information, and means for analyzing user information using the model to detect signs of fraud. This makes it possible to monitor the user's communication data in real time and to quickly warn in the event of potential fraud.

[0690] "Information source" refers to a data provider used to collect information about fraudulent methods.

[0691] A "generative model" is a mechanism for creating predictive algorithms to detect fraudulent activity based on collected data.

[0692] "User" refers to an individual or organization that uses the fraud detection system.

[0693] "Signs of fraud" are specific patterns or indicators that suggest fraudulent activity may be taking place.

[0694] A "warning" is a notification that informs users of the possibility of fraud and serves as a cautionary tale.

[0695] "Communication data" refers to information that users send and receive in digital communications, such as emails, messages, and phone calls.

[0696] "Mobile device" refers to electronic devices such as smartphones and tablets that users can carry with them.

[0697] "Head-mounted display devices" refer to devices such as smart glasses and head-mounted displays that are worn and used by the user.

[0698] The system realizing this invention involves a server and a terminal working together to detect and warn of signs of fraud in real time. The server collects information on fraudulent methods from various sources and uses this information to generate an advanced predictive model for detecting fraudulent activity using a generative model. The generated model is transmitted to the terminal. On the terminal, the user's communication data is monitored in real time, and if signs of fraud are found, a warning is issued quickly. The warning is displayed on the user's mobile device or a head-mounted display device.

[0699] Specifically, the server uses Python or a similar programming environment to analyze diverse data sources on the internet and learn signs of phishing emails and other fraudulent activities. On the terminal side, the collected models are used to analyze emails and messages contained in communications and assess the fraud risk. This allows users to instantly recognize emails containing suspicious links and prevent fraud before it happens.

[0700] For example, when a user receives a message stating, "Your account has been accessed without authorization," the device analyzes this message in real time. If a high risk of fraud is detected, it immediately displays a warning such as, "This message may be a scam." This allows the user to act safely without clicking on any links.

[0701] Examples of prompt messages include the following:

[0702] "Detect whether the following message is a fraud: 'You've won a free vacation. Click here to claim your prize.'"

[0703] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0704] Step 1:

[0705] The server collects data on fraudulent methods from internet sources. Inputs include phishing emails, URLs of fraudulent websites, and summaries of reported fraud cases. This information is collected and stored in a database to prepare the foundational data for generating highly accurate fraud detection models. The output is updates to the fraudulent methods database.

[0706] Step 2:

[0707] The server trains a generative AI model based on the collected data. The input is the fraud-related data collected in Step 1. This is fed into a machine learning algorithm to generate a model for detecting fraudulent activity. During this process, data processing steps such as feature extraction and data normalization are performed. The output is the newly trained fraud detection model.

[0708] Step 3:

[0709] The server sends the trained fraud detection model to the terminal. The input is the fraud detection model generated in step 2. The output is the state change of the terminal, which has received the model and is preparing for analysis.

[0710] Step 4:

[0711] The device monitors the user's communication data in real time using the received fraud detection model. Inputs include emails, messages, and call content sent and received by the user. This data is analyzed in real time to detect signs of fraud. The output is information about the detected signs of fraud.

[0712] Step 5:

[0713] The device immediately displays a warning to the user if signs of fraud are detected. The input is the fraud indicator data obtained in step 4. Based on this data, a warning message is generated to help the user take appropriate action and displayed on the mobile device or head-mounted display device. The output is the warning displayed to the user and the corresponding user action.

[0714] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0715] This invention's system incorporates an emotion engine that recognizes user emotions in addition to a fraud detection function. This allows the system to analyze the user's emotional state based on the detected signs of fraud while the user is using digital communication, and then provide an appropriate response.

[0716] Server Role

[0717] The server collects the latest fraud information from the internet and generates models to detect fraudulent activities. In addition, it prepares the data necessary for the emotion engine and provides a foundation for analyzing the user's emotional state.

[0718] Terminal role

[0719] The device operates using a fraud detection model and sentiment engine provided by the server. With the user's permission, it monitors communication data, voice, and data related to the user's emotions. This data is analyzed in real time to look for signs of fraud.

[0720] The emotion engine identifies the user's emotional state from factors such as voice tone, text content, and behavioral patterns. If fraud is detected and it is determined that the user is experiencing anxiety or stress as a result, the system takes this into account and provides the user with an appropriate warning.

[0721] User feedback and response

[0722] Users can receive emotionally-sensitive advice through warning messages on their devices. For example, if a user is feeling stressed, the warning may be delivered in a gentle tone or display additional support information (such as who they can talk to).

[0723] Specific example

[0724] For example, if a user receives an email requesting an urgent account information update, the device analyzes the email and determines that it is likely a scam. The emotion engine may simultaneously detect that the user's heart rate has increased and they are feeling anxious while reading the email. In this case, the device displays a warning message tailored to the user's emotional state, such as, "This email may be a scam. Please remain calm and contact our support center."

[0725] Furthermore, user feedback is sent to the server and used to improve the fraud detection model and sentiment engine. This allows the system to continuously improve the user experience and strengthen protection against fraud.

[0726] The introduction of this system will reduce the risk of fraud for users, allowing them to continue using the digital world with peace of mind.

[0727] The following describes the processing flow.

[0728] Step 1:

[0729] The server collects data on the latest fraud techniques from publicly available databases on the internet and related sources. This information includes phishing email samples and new fraud methods.

[0730] Step 2:

[0731] The server analyzes the collected data and builds a generative model to detect fraudulent activity. This model is trained using machine learning algorithms to improve its ability to identify new signs of fraud.

[0732] Step 3:

[0733] The server uses an emotion engine to prepare training data for emotion recognition and lay the foundation for understanding various human emotional states.

[0734] Step 4:

[0735] The device receives fraud detection models and sentiment engines provided by the server and monitors the user's communication data in real time. This data includes emails, messages, and voice data.

[0736] Step 5:

[0737] The device uses a fraud detection model to analyze the user's communication data and detect signs of fraud. If a fraudulent email or suspicious link is detected, the information is recorded in detail.

[0738] Step 6:

[0739] The device's emotion engine analyzes the user's emotions from their voice tone and text content. For example, it can determine whether a user is feeling anxious while reading an email.

[0740] Step 7:

[0741] The device will display an emotionally appropriate warning to the user if signs of fraud are detected and the user is feeling anxious. This warning will include appropriate countermeasures and support information.

[0742] Step 8:

[0743] Users review the displayed warnings and select safe actions as needed. For example, they might delete emails suspected of being fraudulent.

[0744] Step 9:

[0745] The user's actions and responses to warnings are sent to the server as feedback. This feedback is used to further improve the generative model and sentiment engine.

[0746] (Example 2)

[0747] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[0748] Traditional fraud detection systems focus on detecting signs of fraud, but they are unable to respond in a way that aligns with the emotional state of users affected by detected fraud. As a result, users' stress and anxiety remain unresolved, and the optimal response is not provided.

[0749] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0750] In this invention, the server includes means for collecting information on the latest fraudulent methods from a communication network, means for generating a model for identifying fraudulent activities using a generative model based on the collected information, and means for identifying the user's emotional state using an emotion analysis device. This makes it possible to provide appropriate warnings and responses according to the user's emotional state, enabling the user to use the digital environment with peace of mind.

[0751] "Communication network" refers to the infrastructure and technologies used to send and receive information, and in particular includes the internet and other digital networks.

[0752] A "generative model" refers to a machine learning model that learns patterns from data and is built to make predictions and classifications on new data.

[0753] "Fraudulent activity" refers to any action or means taken to deceive others with dishonesty or malicious intent.

[0754] An "emotion analysis device" refers to a system that includes technologies and devices that analyze voice, text, behavioral patterns, etc., in order to identify a user's emotional state.

[0755] "Users" refers to individuals or organizations that use the system to provide information or receive services.

[0756] "Real-time" refers to data processing and analysis being carried out in accordance with the passage of time in the real world, meaning that delays are minimized.

[0757] A "warning" refers to a notification or message provided by a system to inform the user of potential dangers or situations that require attention.

[0758] This invention is an advanced digital protection system that combines fraud detection and sentiment recognition. The server automatically acquires data on the latest fraud patterns and techniques from an information network. Based on the collected information, the server builds a fraud detection model using programming languages ​​such as Python and libraries such as Scikit-learn and TensorFlow. This model learns patterns to identify fraudulent activities and analyzes user data. Furthermore, the server prepares the data necessary for sentiment analysis devices and provides a foundation for identifying the user's emotional state.

[0759] The terminal utilizes fraud detection models and sentiment analysis devices provided by the server. With the user's permission, the terminal monitors communication and voice data in real time and analyzes signs of fraud. The sentiment engine implemented on the terminal analyzes voice tone, text content, and behavioral patterns to identify the user's emotional state. Specific software used includes NLTK and Hugging Face Transformers.

[0760] For example, when a user receives an email requesting an urgent account information update, the device immediately analyzes the email's content and detects that it is likely a scam. Simultaneously, the emotion engine may detect an increase in heart rate and determine that the user is feeling anxious. In such cases, the device displays an emotion-sensitive warning message such as, "This email may be a scam. Please remain calm and contact the appropriate department." Examples of these prompts may include, "Please describe the characteristics of a scam email," or "What can help the user feel at ease?"

[0761] Users can receive warnings and advice from the system and provide feedback. This feedback is sent to the server and used to improve the accuracy of the fraud detection model and sentiment analysis device. This allows the system to continuously evolve and provide users with a safer and more comfortable digital experience.

[0762] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0763] Step 1:

[0764] The server retrieves data on the latest fraud patterns from its information network. It uses a list of URLs from news sites and specialized databases as input, collecting information using web scraping techniques. The output is a dataset containing characteristics and related information of fraudulent methods. This dataset is used in the subsequent model generation process.

[0765] Step 2:

[0766] The server builds a generative AI model based on the data collected in Step 1. It receives a dataset of fraud features as input and trains the model using machine learning algorithms with Scikit-learn or TensorFlow. The output is a classification model for fraud detection. This model is used to distinguish between fraud and normal behavior.

[0767] Step 3:

[0768] The server prepares data for the emotion analysis device. It collects emotion label information based on speech and text as input, and constructs a dataset using NLTK and Hugging Face Transformers. The output is a dataset that serves as a baseline for identifying the user's emotional state. This dataset is used for emotion analysis on the terminal.

[0769] Step 4:

[0770] The terminal receives a fraud detection model and sentiment analysis device provided by the server and executes them on the user's device. It monitors the user's communication data and voice data as input. The output is real-time fraud detection results and identification of emotional states. Specifically, it analyzes emails and call content to immediately identify signs of fraud and changes in emotion.

[0771] Step 5:

[0772] The device generates and displays a warning message to the user based on detected fraud signs and emotional state. It uses the results of fraud model detection and sentiment analysis as input. The output is a customized warning message tailored to the user's situation, such as, "This may be a scam. Please remain calm."

[0773] Step 6:

[0774] Users receive warnings from their devices, take necessary actions, and provide feedback based on their experience. Input consists of the warning content and the user's personal response experience, which are used to generate feedback. Output is improvement suggestions and experience evaluations sent to the server. This feedback is used for the continuous improvement of the system.

[0775] (Application Example 2)

[0776] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[0777] In modern electronic financial transactions, fraudulent activities are becoming increasingly sophisticated, making it difficult for users to trade online with confidence. Furthermore, users who encounter signs of fraud often experience anxiety and stress, which can impair their ability to make rational decisions. In this context, there is a need not only to quickly detect signs of fraud but also to provide appropriate warnings and support that take into account the user's emotional state.

[0778] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.

[0779] In this invention, the server includes means for collecting information on the latest fraudulent methods from the internet, means for generating a model for detecting fraudulent activity using a generative model based on the collected information, and means for analyzing user information using the model to detect signs of fraud. This makes it possible to analyze the user's communication information in real time and immediately issue a warning, taking into account the emotional state, if there is a possibility of fraud.

[0780] "Fraudulent practices" are means or techniques used to deceive users and extort money or personal information from them.

[0781] A "generative model" is a method for generating algorithms to detect fraudulent activity using collected data.

[0782] "Emotional state" refers to the user's psychological and physiological emotional state, which includes anxiety, stress, tension, etc.

[0783] "Adjusting the wording of warnings" means changing the content and tone of warning messages according to the user's emotional state.

[0784] "Communication information" refers to data that users send and receive through electronic devices, and includes voice, text, and other digital information.

[0785] "Real-time analysis" means processing the data almost instantly after it is acquired and obtaining the results.

[0786] The system for implementing this invention is intended to consist of a server and terminals, and to operate in coordination with each other.

[0787] The server is responsible for collecting information on the latest fraud techniques from the internet. This is done through web crawling technologies and APIs, and stored in a database as needed. Based on this information, the server uses AI generative models (e.g., custom models using TensorFlow) to generate analytical models for detecting fraudulent activity. For analyzing emotional states, it uses speech analysis libraries (e.g., Google Speech-to-Text API).

[0788] The terminal retrieves the generative model from the server and analyzes the user's communication information (voice, text, etc.) in real time. If signs of fraud are detected through this analysis, the emotional state is evaluated. For example, changes in voice or behavioral patterns are interpreted as emotional states. Based on this emotional state, the terminal adjusts the content and tone of the warning message and presents it to the user. This helps the user to calmly assess the situation.

[0789] Users can submit feedback on warnings provided from their devices. This feedback is returned to the server and used to improve the fraud detection and sentiment analysis models. By collecting and applying feedback, the system is continuously updated, enabling more sophisticated fraud prevention measures.

[0790] As a concrete example, when a user attempts to purchase an expensive item from a new online shop, the device analyzes the transaction and, if it determines there is a high risk of fraud, checks the user's emotional state. For instance, if it detects signs of anxiety and an elevated heart rate, the device displays a gentle message such as, "This transaction carries a risk of fraud. Further details are recommended."

[0791] An example of a prompt message is: "A user is attempting to make a large online payment. If there are signs of fraud, how should a warning be issued? Also, design an effective, emotion-based warning message."

[0792] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0793] Step 1:

[0794] The server collects information about fraudulent methods from the internet. Using web crawling technology and APIs, it retrieves the latest fraud-related data and stores it in a database. This prepares the information in a format that can be used to generate fraud models.

[0795] Step 2:

[0796] The server creates a fraud detection model using a generative AI model (e.g., TensorFlow) based on the collected data. The latest fraud information is used as input, and the detection model is obtained as output. The generated model is then used to analyze user data.

[0797] Step 3:

[0798] The device retrieves a fraud detection model from the server and begins real-time analysis of the user's communication information (voice, text, etc.). It analyzes the user's communication data as input and outputs a detection result if there are signs of fraud.

[0799] Step 4:

[0800] The device evaluates the user's emotional state in response to detected signs of fraud. Using a speech analysis library (e.g., Google Speech-to-Text API), it analyzes the emotional state using voice tone and behavioral patterns as input. Based on this, changes in emotion are output.

[0801] Step 5:

[0802] The device adjusts warning messages based on the analyzed emotional state. It receives the emotional state and fraud detection results as input and generates and displays a warning with appropriate content and tone to the user.

[0803] Step 6:

[0804] The user reviews the warning message displayed on the device and provides feedback as needed. The user's feedback is sent to the server for system improvement. The user's response is received as input, and feedback information is returned to the server.

[0805] Step 7:

[0806] The server updates its fraud detection and sentiment analysis models based on user feedback. Feedback information is provided as input, which adjusts the models, resulting in improved models as output. This cycle allows the system to continuously improve.

[0807] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0808] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0809] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.

[0810] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[0811] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.

[0812] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.

[0813] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.

[0814] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.

[0815] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."

[0816] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values ​​representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.

[0817] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.

[0818] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.

[0819] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.

[0820] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[0821] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.

[0822] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.

[0823] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.

[0824] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.

[0825] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.

[0826] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.

[0827] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.

[0828] The following is further disclosed regarding the embodiments described above.

[0829] (Claim 1)

[0830] Methods for gathering information on the latest fraud techniques from the internet,

[0831] A means for generating a model to detect fraudulent activity using a generative model based on collected information,

[0832] A means for analyzing user data using the aforementioned model and detecting signs of fraud,

[0833] A means of displaying a warning to the user based on the detected signs,

[0834] A system that includes this.

[0835] (Claim 2)

[0836] The system according to claim 1, further comprising means for receiving user feedback and incorporating it into improvements to the generative model.

[0837] (Claim 3)

[0838] The system according to claim 1, comprising means for analyzing user communication data in real time and immediately issuing a warning if there is a possibility of fraud.

[0839] "Example 1"

[0840] (Claim 1)

[0841] A means of collecting information on fraudulent methods in digital communications from the communication network,

[0842] A means for generating a logical structure for detecting fraudulent activity using a machine learning model generated based on collected information,

[0843] A means for analyzing user information using the aforementioned logical structure and detecting signs of fraudulent activity,

[0844] A means of displaying a warning to the user based on the detected signs,

[0845] A system that includes this.

[0846] (Claim 2)

[0847] The system according to claim 1, further comprising means for receiving user feedback and reflecting it in improving the logical structure.

[0848] (Claim 3)

[0849] The system according to claim 1, comprising means for immediately analyzing a user's communication information and immediately issuing a warning if there is a possibility of fraudulent activity.

[0850] "Application Example 1"

[0851] (Claim 1)

[0852] Means of gathering information on the latest fraud techniques from various sources,

[0853] A means for generating a model to detect fraudulent activity using a generative model based on collected information,

[0854] A means for analyzing user information using the aforementioned model and detecting signs of fraud,

[0855] A means of displaying a warning to the user based on the detected signs,

[0856] A means to monitor users' communication data in real time and quickly warn them if there is a possibility of fraud,

[0857] A system that includes this.

[0858] (Claim 2)

[0859] The system according to claim 1, further comprising means for receiving feedback from users and reflecting it in the optimization of the generation model.

[0860] (Claim 3)

[0861] The system according to claim 1, further comprising means for displaying the warning on the user's mobile device or head-mounted display device.

[0862] "Example 2 of combining an emotion engine"

[0863] (Claim 1)

[0864] A means of collecting information on the latest fraud techniques from the communication network,

[0865] A means for generating a model to identify fraudulent activities using a generative model based on collected information,

[0866] A means for analyzing user information using the aforementioned model and detecting signs of fraud,

[0867] A means for identifying the emotional state of a user using an emotion analysis device,

[0868] A means of providing appropriate warnings to the user based on detected signs and identified emotional states,

[0869] A system that includes this.

[0870] (Claim 2)

[0871] The system according to claim 1, further comprising means for receiving feedback from users and reflecting it in improvements to the generative model and the emotion analysis device.

[0872] (Claim 3)

[0873] The system according to claim 1, comprising means for analyzing a user's communication information in real time and immediately issuing a warning if there is a possibility of fraud.

[0874] "Application example 2 when combining with an emotional engine"

[0875] (Claim 1)

[0876] Methods for gathering information on the latest fraud techniques from the internet,

[0877] A means for generating a model to detect fraudulent activity using a generative model based on collected information,

[0878] A means for analyzing user information using the aforementioned model and detecting signs of fraud,

[0879] A means of analyzing the user's emotional state based on the detected signs,

[0880] A means of adjusting the expression of a warning according to the analyzed emotional state,

[0881] A system that includes this.

[0882] (Claim 2)

[0883] The system according to claim 1, further comprising means for receiving user feedback and reflecting it in improving the generative model and the sentiment analysis model.

[0884] (Claim 3)

[0885] The system according to claim 1, comprising means for analyzing a user's communication information in real time and immediately issuing a warning, taking into account the emotional state, if there is a possibility of fraud. [Explanation of symbols]

[0886] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>

Claims

1. Means of gathering information on the latest fraud techniques from various sources, A means for generating a model to detect fraudulent activity using a generative model based on collected information, A means for analyzing user information using the aforementioned model and detecting signs of fraud, A means of displaying a warning to the user based on the detected signs, A means to monitor users' communication data in real time and quickly warn them if there is a possibility of fraud, A system that includes this.

2. The system according to claim 1, further comprising means for receiving feedback from users and reflecting it in the optimization of the generation model.

3. The system according to claim 1, further comprising means for displaying the warning on the user's mobile device or head-mounted display device.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A